Queries, Representation & Detection: The Next 100 Model Fingerprinting Schemes

Augustin Godinot1,2,3,4, Erwan Le Merrer2, Camilla Penzo4, François Taïani1,2,3, Gilles Tredan5,6

1Université de Rennes 2Inria 3IRISA/CNRS 4PEReN 5LAAS 6CNRS

AAAI25arXivpostercodescholar
QuRD logo
Figure 1: When SoTa gives you lemons, you make LemonQuRD

When auditing a machine learning (ML) model, regardless of the access the auditor might have to the model, there is always the risk of the ModelSwap™ attack. Think of the Dieselgate scandal. I show you a very compliant, albeit less powerful model during the audit but swap it for an other model when serving the users. A way to mitigate the ModelSwap™ attack is to monitor the user-facing model and check if it is the same that we saw during the audit.

Beyond auditing, comparing models is a fundamental task in ML. Perfomance evaluation, performance prediction, model provenance, model ownership resolution, unlearning verification are all based on some notion of (pseudo)-metric between models.