Pith. sign in

REVIEW 1 cited by

WET: Overcoming Paraphrasing Vulnerabilities in Embeddings-as-a-Service with Linear Transformation Watermarks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2409.04459 v2 pith:5HSLW6D7 submitted 2024-08-29 cs.CR cs.CLcs.LG

classification cs.CRcs.CLcs.LG
keywords eaasmodelembeddingsparaphrasingwatermarksattackscloneembeddings-as-a-service
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Embeddings-as-a-Service (EaaS) is a service offered by large language model (LLM) developers to supply embeddings generated by LLMs. Previous research suggests that EaaS is prone to imitation attacks -- attacks that clone the underlying EaaS model by training another model on the queried embeddings. As a result, EaaS watermarks are introduced to protect the intellectual property of EaaS providers. In this paper, we first show that existing EaaS watermarks can be removed by paraphrasing when attackers clone the model. Subsequently, we propose a novel watermarking technique that involves linearly transforming the embeddings, and show that it is empirically and theoretically robust against paraphrasing.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Your Semantic-Independent Watermark is Fragile: A Semantic Perturbation Attack against EaaS Watermark

    cs.CR 2024-11 conditional novelty 5.0 of 10

    SPA identifies and removes backdoor-watermarked embeddings from EaaS responses by exploiting the constant watermark vector added to triggered text, bypassing verification.

Pith tools