Return
Zero-Knowledge Proof-Based IP Protection of Visual Large Models of Autonomous Driving
C
L
X
Z
Z
Z
DOI:10.1109/tifs.2026.3716233.png)
Abstract
En 中文
Visual Large Models (VLMs) are revolutionizing passenger and cargo transportation through autonomous driving (AD), but their immense commercial value also exacerbates the risk of intellectual property (IP) infringement. Model watermarking, a primary IP protection method for deep learning assets, inadvertently degrades model performance, which is unacceptable for safety-critical AD applications. Moreover, traditional IP verification involving third parties introduces vulnerabilities to data and model leakage, potentially jeopardizing both sensitive transportation data and IP of the AD system itself. To tackle aforementioned challenges, this paper introduces a novel IP protection framework for VLMs leveraging zero-knowledge proof technology. Initially, to avoid performance degradation of VLMs in perceiving complex traffic scenarios, this paper proposes a model fingerprinting method incorporating a prior-knowledge-free sample discrimination module. This module quantifies the correlation between samples and decision boundaries using cross-entropy loss, assigning higher weights to high-discriminability samples situated near these boundaries, and fuses the weight matrix with the sample correlation matrix to generate an enhanced fingerprint. This significantly improves the distinguishability between stolen and irrelevant models. Following this, the paper presents an IP verification protocol called zk-DeepIP for VLM, underpinned by zero-knowledge proof, ensuring robust security for AD systems the verification process while remaining compatible with existing IP verification methods. Finally, this paper evaluates the performance of our proposed model fingerprinting technique on CIFAR-10 datasets, where experimental results reveal that the average AUC score improves by 0.03 across various attacks, datasets, and models. Furthermore, in transfer learning scenarios on CIFAR-100 and CIFAR10-c, the average Area Under the Curve (AUC) score increases by 0.12. Notably, the zk-DeepIP protocol effectively safeguards the privacy of both perception models and their associated test cases, ensuring the integrity and security of IP.
Keywords:
Visual large models
model fingerprinting
IP protection
zero-knowledge proof
sample correlation
Journal
IF:
8
Papers:
5.2K
Citations:
2.3W
