Pith. sign in

REVIEW 2 cited by

Watermarking Vision-Language Pre-trained Models for Multi-modal Embedding as a Service

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2311.05863 v1 pith:45WU4TWZ submitted 2023-11-10 cs.CR cs.CV

classification cs.CRcs.CV
keywords modelvlpsembeddingeaaswatermarkingattackscopyrightdata
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recent advances in vision-language pre-trained models (VLPs) have significantly increased visual understanding and cross-modal analysis capabilities. Companies have emerged to provide multi-modal Embedding as a Service (EaaS) based on VLPs (e.g., CLIP-based VLPs), which cost a large amount of training data and resources for high-performance service. However, existing studies indicate that EaaS is vulnerable to model extraction attacks that induce great loss for the owners of VLPs. Protecting the intellectual property and commercial ownership of VLPs is increasingly crucial yet challenging. A major solution of watermarking model for EaaS implants a backdoor in the model by inserting verifiable trigger embeddings into texts, but it is only applicable for large language models and is unrealistic due to data and model privacy. In this paper, we propose a safe and robust backdoor-based embedding watermarking method for VLPs called VLPMarker. VLPMarker utilizes embedding orthogonal transformation to effectively inject triggers into the VLPs without interfering with the model parameters, which achieves high-quality copyright verification and minimal impact on model performance. To enhance the watermark robustness, we further propose a collaborative copyright verification strategy based on both backdoor trigger and embedding distribution, enhancing resilience against various attacks. We increase the watermark practicality via an out-of-distribution trigger selection approach, removing access to the model training data and thus making it possible for many real-world scenarios. Our extensive experiments on various datasets indicate that the proposed watermarking approach is effective and safe for verifying the copyright of VLPs for multi-modal EaaS and robust against model extraction attacks. Our code is available at https://github.com/Pter61/vlpmarker.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SWAP: Towards Copyright Auditing of Soft Prompts via Sequential Watermarking

    cs.CR 2025-11 conditional novelty 7.0 of 10

    SWAP embeds a copyright watermark into CLIP soft prompts by enforcing a secret ordering of out-of-distribution class scores, enabling black-box ownership verification.

  2. BESA: Boosting Encoder Stealing Attack with Perturbation Recovery

    cs.CR 2025-06 reject novelty 4.0 of 10

    BESA boosts encoder stealing attacks under perturbation defenses by detecting the defense and recovering clean feature vectors with a MagNet-style generator.

Pith tools