Latent Copyright Space for Model Provenance
Abstract
Model provenance and intellectual property protection are becoming increasingly important as trained models are treated as valuable digital assets and widely released, fine-tuned, and redistributed. A common approach is to embed ownership information into the model for subsequent verification. However, once a model is released and adapted to downstream tasks, the embedded ownership signals may be gradually weakened or even erased during fine-tuning. In this paper, we introduce a new concept, termed the latent copyright space, to capture such invariant characteristics of model derivation under downstream adaptation. Specifically, given a source model, we first construct a private low-dimensional space using a secret key. The source model is then minimally adjusted so that its projection into this space matches a prescribed copyright identity, with negligible effect on its original utility. After release, the model can be adapted using standard downstream training procedures. To verify a target model, we project it into the same copyright space and measure its consistency with the protected source. Models derived from the protected source are expected to preserve the encoded identity under downstream adaptation, whereas non-derived models exhibit lower identity consistency. Experimental results across vision and language models show that the proposed method can effectively distinguish models derived from a protected source from non-derived models under diverse downstream adaptation settings.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.