{"id":"https://openalex.org/W4403444365","doi":"https://doi.org/10.48550/arxiv.2410.08604","title":"MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models","display_name":"MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models","publication_year":2024,"publication_date":"2024-10-11","ids":{"openalex":"https://openalex.org/W4403444365","doi":"https://doi.org/10.48550/arxiv.2410.08604"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2410.08604","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.08604","pdf_url":"https://arxiv.org/pdf/2410.08604","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2410.08604","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5114285439","display_name":"Shojiro Yamabe","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Yamabe, Shojiro","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5114285440","display_name":"Tsubasa Takahashi","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Waseda, Futa","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5114285441","display_name":"Futa Kai Waseda","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Takahashi, Tsubasa","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5114285442","display_name":"Koki Wataoka","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wataoka, Koki","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5114285439"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T13877","display_name":"Law in Society and Culture","score":0.9300000071525574,"subfield":{"id":"https://openalex.org/subfields/3308","display_name":"Law"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T13877","display_name":"Law in Society and Culture","score":0.9300000071525574,"subfield":{"id":"https://openalex.org/subfields/3308","display_name":"Law"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T12380","display_name":"Authorship Attribution and Profiling","score":0.9221000075340271,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10828","display_name":"Biometric Identification and Security","score":0.9096999764442444,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5844224095344543}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5844224095344543}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2410.08604","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.08604","pdf_url":"https://arxiv.org/pdf/2410.08604","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2410.08604","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2410.08604","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2410.08604","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.08604","pdf_url":"https://arxiv.org/pdf/2410.08604","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4403444365.pdf"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052","https://openalex.org/W4402327032"],"abstract_inverted_index":{"Protecting":[0],"the":[1,15,137],"intellectual":[2],"property":[3],"of":[4,18,36,39,80],"Large":[5],"Language":[6],"Models":[7],"(LLMs)":[8],"has":[9],"become":[10],"increasingly":[11],"critical":[12],"due":[13,41],"to":[14,42,59,93,131,160],"high":[16],"cost":[17],"training.":[19],"Model":[20],"merging,":[21,154],"which":[22,75],"integrates":[23],"multiple":[24],"expert":[25],"models":[26],"into":[27],"a":[28,33,70,96,115,142],"single":[29],"multi-task":[30],"model,":[31],"introduces":[32],"novel":[34,71],"risk":[35],"unauthorized":[37],"use":[38],"LLMs":[40,150],"its":[43],"efficient":[44],"merging":[45,61],"process.":[46],"While":[47],"fingerprinting":[48,72],"techniques":[49],"have":[50],"been":[51],"proposed":[52],"for":[53,101,145],"verifying":[54],"model":[55,60,82,97,107,117,162],"ownership,":[56],"their":[57],"resistance":[58,159],"remains":[62],"unexplored.":[63],"To":[64],"address":[65],"this":[66],"gap,":[67],"we":[68,135],"propose":[69],"method,":[73],"MergePrint,":[74],"embeds":[76],"robust":[77],"fingerprints":[78,124],"capable":[79],"surviving":[81],"merging.":[83,129],"MergePrint":[84,122,140],"enables":[85],"black-box":[86,146],"ownership":[87,147],"verification,":[88,148],"where":[89],"owners":[90],"only":[91],"need":[92],"check":[94],"if":[95],"produces":[98],"target":[99],"outputs":[100],"specific":[102],"fingerprint":[103,138],"inputs,":[104],"without":[105],"accessing":[106],"weights":[108],"or":[109],"intermediate":[110],"outputs.":[111],"By":[112],"optimizing":[113],"against":[114],"pseudo-merged":[116],"that":[118,125],"simulates":[119],"merged":[120],"behavior,":[121],"ensures":[123],"remain":[126],"detectable":[127],"after":[128],"Additionally,":[130],"minimize":[132],"performance":[133],"degradation,":[134],"pre-optimize":[136],"inputs.":[139],"pioneers":[141],"practical":[143],"solution":[144],"protecting":[149],"from":[151],"misappropriation":[152],"via":[153],"while":[155],"also":[156],"excelling":[157],"in":[158],"broader":[161],"theft":[163],"threats.":[164]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-02-09T09:26:11.010843","created_date":"2024-10-16T00:00:00"}
