Watermarking Graph Neural Networks via Explanations for Ownership Protection
Researchers have introduced a novel method for protecting the intellectual property of Graph Neural Networks (GNNs) through explanation-based watermarking. As GNNs become increasingly valuable in industrial applications, safeguarding them from unauthorized use is critical. Existing watermarking techniques often fail to address graph data specifically or rely on backdoor methods that manipulate training data, leading to ownership ambiguity and vulnerability to data poisoning attacks. This new approach embeds ownership information directly into GNN explanations, ensuring they are statistically distinct without altering the underlying data. This eliminates data dependencies and ambiguity while retaining the benefits of black-box verification. The authors theoretically prove that locating the watermark is NP-hard, even with full knowledge of the method. Empirical tests demonstrate the technique's robustness against common threats such as fine-tuning and pruning attacks. By addressing the limitations of current methods, this research significantly advances the security and protection of GNN intellectual property, offering a more reliable solution for model ownership verification in artificial intelligence systems.
Wire timeline
Watermarking Graph Neural Networks via Explanations for Ownership Protection
Researchers have introduced a novel method for protecting the intellectual property of Graph Neural Networks (GNNs) through explanation-based watermarking. As GNNs become increasingly valuable in industrial applications, safeguarding them from unauthorized use is critical. Existing watermarking techniques often fail to address graph data specifically or rely on backdoor methods that manipulate training data, leading to ownership ambiguity and vulnerability to data poisoning attacks. This new approach embeds ownership information directly into GNN explanations, ensuring they are statistically distinct without altering the underlying data. This eliminates data dependencies and ambiguity while retaining the benefits of black-box verification. The authors theoretically prove that locating the watermark is NP-hard, even with full knowledge of the method. Empirical tests demonstrate the technique's robustness against common threats such as fine-tuning and pruning attacks. By addressing the limitations of current methods, this research significantly advances the security and protection of GNN intellectual property, offering a more reliable solution for model ownership verification in artificial intelligence systems.
cs.AI updates on arXiv.org