GSPS: Global Style-guided Protection Synthesis for Ownership Verification and Leakage Tracing of Unlabeled Datasets in Semi-Supervised Learning
Abstract
Curated unlabeled datasets are valuable assets for semi-supervised learning (SSL), yet remain vulnerable to unauthorized copying, redistribution, and reuse. Protecting such datasets is challenging because conventional watermarking methods often rely on stable label supervision, while SSL operates largely on unlabeled data and employs strong augmentations that can disrupt watermark signals. Moreover, existing methods mainly support binary ownership verification and cannot trace leaked copies to specific recipients under black-box auditing. To address these challenges, we propose GSPS, a Global Style-guided Protection Synthesis framework for ownership verification and recipient-specific leakage tracing of unlabeled text datasets. GSPS first identifies reliable watermark carriers without human annotations using -based selection for text classification and multi-model cooperation for LLM-based reasoning and question answering. It then introduces Quad-Dimensional Adaptive Style Selection (QASS) to identify robust global watermark styles and integrates recipient-specific orthogonal fingerprints into the selected style to generate distinguishable dataset copies. During black-box auditing, GSPS performs statistical ownership verification and recipient-specific leakage attribution. Extensive experiments on Chinese and English datasets, multiple SSL algorithms, and both text classification and LLM-based reasoning and question-answering tasks demonstrate that GSPS achieves up to 90% watermark success rate and over 95% trace accuracy at only a 1% watermarking rate, with negligible utility degradation and strong robustness against state-of-the-art defenses.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.