COPYCOP: Ownership Verification for Graph Neural Networks
Researchers Rahul Nandakumar and Deepayan Chakrabarti have introduced COPYCOP, a novel algorithm designed to verify ownership and detect copycat Graph Neural Networks (GNNs). The study addresses the challenge of determining whether two GNNs were trained independently or if one was adversarially trained to mimic the other's node embeddings. Unlike existing watermarking and fingerprinting methods, COPYCOP can identify such relationships even when the models possess different architectures, weights, and embedding dimensions, and when the adversary applies transformations to obscure the connection. The authors provide theoretical guarantees for the algorithm's efficacy. Extensive experiments conducted across 14 datasets and five distinct GNN architectures demonstrate that COPYCOP is both accurate and robust against a broad class of adversarial attacks and transformations. This development offers a significant advancement in protecting intellectual property in machine learning models. The associated code has been made available to the community via an anonymous repository, facilitating further research and verification of the proposed method's capabilities in securing AI model integrity.
Wire timeline
COPYCOP: Ownership Verification for Graph Neural Networks
Researchers Rahul Nandakumar and Deepayan Chakrabarti have introduced COPYCOP, a novel algorithm designed to verify ownership and detect copycat Graph Neural Networks (GNNs). The study addresses the challenge of determining whether two GNNs were trained independently or if one was adversarially trained to mimic the other's node embeddings. Unlike existing watermarking and fingerprinting methods, COPYCOP can identify such relationships even when the models possess different architectures, weights, and embedding dimensions, and when the adversary applies transformations to obscure the connection. The authors provide theoretical guarantees for the algorithm's efficacy. Extensive experiments conducted across 14 datasets and five distinct GNN architectures demonstrate that COPYCOP is both accurate and robust against a broad class of adversarial attacks and transformations. This development offers a significant advancement in protecting intellectual property in machine learning models. The associated code has been made available to the community via an anonymous repository, facilitating further research and verification of the proposed method's capabilities in securing AI model integrity.
cs.AI updates on arXiv.org