[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-128455-en":3,"doc-seo-128455-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},128455,962085662650,"Jiven","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Identifying Appropriate Intellectual Property Protection Mechanisms for Machine Learning Models - A Systematization of Watermarking, Fingerprinting, Model Access, and Attacks","Machine learning model commercialization is accelerating, while training powerful models increasingly demands high cost and expertise, making intellectual property protection for trained models a pressing concern. Existing ML IPP research remains fragmented due to a missing unified view and common taxonomy of threats, attacks, and defenses. This work systematizes the state of the field, builds a comprehensive threat model, and organizes attacks and defenses into a unified taxonomy to bridge ML and security perspectives.","Identifying Appropriate Intellectual Property Protection Mechanisms for Machine Learning Models: A Systematization of Watermarking, Fingerprinting, Model Access, and Attacks  \nIsabell Lederer1 and Rudolf Mayer2 and Andreas Rauber3  \narXiv :2304 . 11285v1 [ cs .LG] 22 Apr 2023  \nAbstract—The commercial use of Machine Learning (ML) is spreading; at the same time, ML models are becoming more complex and more expensive to train, which makes Intellectual Property Protection (IPP) of trained models a pressing issue. Unlike other domains that can build on a solid understanding of the threats, attacks and defenses available to protect their IP, the ML-related research in this regard is still very fragmented. This is also due to a missing uniﬁed view as well as a common taxonomy of these aspects.  \nIn this paper, we systematize our ﬁndings on IPP in ML, while focusing on threats and attacks identiﬁed and defenses proposed at the time of writing. We develop a comprehensive threat model for IP in ML, categorizing attacks and defenses within a uniﬁed and consolidated taxonomy, thus bridging research from both the ML and security communities.  \nIndex Terms—Machine Learning, Intellectual Property Protection, Watermarking, Fingerprinting, Model Access Control, Attacks on Intellectual Property Protection  \nI. INTRODUCTION  \nIn many Machine Learning (ML) settings, training an effective model from scratch – especially complex and powerful models such as a Deep Neural Network (DNN) – (i) is computationally very expensive, (ii) requires expertise for setting parameters, and (iii) the amount of data needed is not commonly accessible or expensive to obtain. Security concerns become more prominent when these models are made available to other parties or customers, e.g., in Machine Learning asa Service (MLaaS) or under a license. This is when model owners – who have invested signiﬁcant resources to train a model and now want to offer it to customers – start to consider Intellectual Property Protection (IPP) methods like watermarking (to verify ownership) and access control (to prevent unauthorized usage of a model) . IP litigation cases over ML models do occur, but have so far not seen widespread media attention; however, protection mechanisms are therefore investigated from a legal point of view, e.g., [1], showing that  \nThis work was partially funded by the European Union's Horizon 2020 research and innovation programme under grant agreement no. 826078 (project 'FeatureCloud') . This publication reﬂects only the authors' view and the European Commission is not responsible for any use that may be made of the information it contains. SBA Research (SBA-K1) is a COMET Center within the COMET – Competence Centers for Excellent Technologies Programme and funded by BMK, BMAW, and the federal state of Vienna. The COMET Programme is managed by FFG.  \n1Isabell Lederer was with SBA Research, Vienna, Austria while working on this paper.  \n2Rudolf Mayer is with SBA Research, Vienna, Austria, and the Institute of Information Systems Engineering, Faculty of Informatics, Vienna University  \nof Technology, Vienna, Austria. Email: [rmayer@sba-research.org](rmayer@sba-research.org)  \n3Andreas Rauber is with SBA Research, Vienna, Austria, and the Institute of Information Systems Engineering, Faculty of Informatics, Vienna University of Technology, Vienna, Austria. Email: [andreas.rauber@tuwien.ac.at](andreas.rauber@tuwien.ac.at)  \nthe burden of proof is generally lies with the IP rights holder. Thus, it is important to anticipate the need for such proofs and protect ML models with IPP techniques.  \nIn the last few years, we have consequently seen an increase in research on IPP techniques for ML models. Many blackand white-box watermarking methods have been proposed based on techniques such as backdoor embedding via data poisoning or regularization. At the same time, several studies have shown the vulnerability of some of these schemes against novel attacks. Similar o","cbCaisZNZPDxKCfq","https://ap.wps.com/l/cbCaisZNZPDxKCfq","pdf",7594608,2,1,19,"English","en",105,"# Introduction\n# Related Work\n# Methodology\n# Background: ML, DNN, Watermarking, Fingerprinting\n# Taxonomy, Threat Model, and Attacks\n# Watermarking and Fingerprinting Approaches\n# Proactive IPP: Access Control\n# Attacks Taxonomy and Vulnerabilities\n# Guidelines for Choosing IPP Methods\n# Conclusions","[{\"question\":\"Why is intellectual property protection important for machine learning models?\",\"answer\":\"Training effective ML models is costly and complex, and models are often shared via services or licensing. Owners need protections such as watermarking and access control to manage unauthorized use and ownership claims.\"},{\"question\":\"What is the main gap this paper addresses in ML IPP research?\",\"answer\":\"The research landscape lacks a unified view and a common taxonomy that consistently organizes threats, attacks, and defenses across the ML and security communities.\"},{\"question\":\"How does the paper structure IPP and evaluate threats and defenses?\",\"answer\":\"It develops a comprehensive threat model and categorizes attacks and defenses within a unified, consolidated taxonomy, including analysis of vulnerabilities to attacks designed to break IPP schemes.\"}]","Identifying Appropriate Intellectual Property Protection Mechanisms for Machine Learning Models - A Systematization of Watermarking, Fingerprinting, Model Access, and Attacks | PDF",1786001157,48,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"identifying-appropriate-intellectual-property-protection-mechanisms-for-machine-learning-models-a-systematization-of-watermarking-fingerprinting-model-access-and-attacks","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/identifying-appropriate-intellectual-property-protection-mechanisms-for-machine-learning-models-a-systematization-of-watermarking-fingerprinting-model-access-and-attacks/128455/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-23","2026-08-06",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why is intellectual property protection important for machine learning models?","Question",{"text":76,"@type":77},"Training effective ML models is costly and complex, and models are often shared via services or licensing. Owners need protections such as watermarking and access control to manage unauthorized use and ownership claims.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What is the main gap this paper addresses in ML IPP research?",{"text":81,"@type":77},"The research landscape lacks a unified view and a common taxonomy that consistently organizes threats, attacks, and defenses across the ML and security communities.",{"name":83,"@type":74,"acceptedAnswer":84},"How does the paper structure IPP and evaluate threats and defenses?",{"text":85,"@type":77},"It develops a comprehensive threat model and categorizes attacks and defenses within a unified, consolidated taxonomy, including analysis of vulnerabilities to attacks designed to break IPP schemes.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":107,"slug":138},"General","general"]