Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

IrisFP: Adversarial-Example-based Model Fingerprinting with Enhanced Uniqueness and Robustness

About

We propose IrisFP, a novel adversarial-example-based model fingerprinting framework that enhances both uniqueness and robustness by leveraging multi-boundary characteristics, multi-sample behaviors, and fingerprint discriminative power assessment to generate composite-sample fingerprints. Three key innovations make IrisFP outstanding: 1) It positions fingerprints near the intersection of all decision boundaries - unlike prior methods that target a single boundary - thus increasing the prediction margin without placing fingerprints deep inside target class regions, enhancing both robustness and uniqueness; 2) It constructs composite-sample fingerprints, each comprising multiple samples close to the multi-boundary intersection, to exploit collective behavior patterns and further boost uniqueness; and 3) It assesses the discriminative power of generated fingerprints using statistical separability metrics developed based on two reference model sets, respectively, for pirated and independently-trained models, retains the fingerprints with high discriminative power, and assigns fingerprint-specific thresholds to such retained fingerprints. Extensive experiments show that IrisFP consistently outperforms state-of-the-art methods, achieving reliable ownership verification by enhancing both robustness and uniqueness.

Ziye Geng, Guang Yang, Yihang Chen, Changqing Luo• 2026

Related benchmarks

TaskDatasetResultRank
Model FingerprintingCIFAR-100
AUC100
52
Model FingerprintingMNIST
AUC0.985
47
Model FingerprintingCIFAR-10
AUC1
47
Model FingerprintingTiny-ImageNet
AUC1
45
Model FingerprintingFashion MNIST
AUC99.2
40
Fingerprint GenerationFashion MNIST
Time Overhead1
15
Model Ownership VerificationTiny-ImageNet
Fidelity Score (FT)97.9
10
Model Ownership VerificationFashion MNIST
Fidelity Transfer (FT)97.5
5
Model Ownership VerificationMNIST
Fidelity (FT)98.3
5
Model Ownership VerificationCIFAR-10
FT98.1
5
Showing 10 of 11 rows

Other info

Follow for update