Fingerprinting Multimodal Large Language Models
Chao Huang, Meng Tong, Kejiang Chen
Abstract
While multimodal large language models (MLLMs) enable a wide range of image-text reasoning tasks, recent incidents indicate that they are vulnerable to illicit deployment and unauthorized distillation. Existing solutions for model provenance are typically confounded by shared language backbones in MLLMs and struggle to detect violations of distillation. To bridge this gap and safeguard model ownership, we present the first study on multimodal model fingerprinting. Inspired by recent findings that self-attention acts as a low-pass filter and that its low-frequency components are informative, we develop AttnPrint for white-box provenance. Specifically, we extract cross-modal attention distributions and isolate their low-frequency components to serve as model fingerprints. To facilitate black-box auditing, we further introduce DistillTrace, which employs hypothesis testing of MLLM outputs to identify potential model infringement. We conduct extensive experiments on 154 model instances across 19 multimodal architectures. Notably, AttnPrint achieves strong derivative-model detection performance while remaining robust to five downstream modification techniques. DistillTrace also provides evidence of distillation relationships under three parameter-independent techniques.
Create a lesson
Related papers
Inference-Engine Fingerprinting Attacks are Practical: Exploring Model-Driven Environmental Discovery, Exploitation, and Escape
Sarah Radway, Andrew Cheng, Vijay Janapa Reddi et al.
Weather Data Spoofing Attacks on Rain-Adaptive Millimeter-Wave Frequency Selection in V2X Communication Networks
Rasheed Bello, Idreez Yusuf, Justice Adjei Owusu et al.
Empirical Analysis of Randomness Quality in Differential Privacy Mechanisms
Cesare Gerolimetto Fabrello, Valeria Rossi, Alberto Trombetta et al.
Towards TEE-Certified DP: Verifiable Differentially Private Training on Legacy GPUs
Li Ge, Wenjie Qu, Weitao Feng et al.
The More It Says, the More You Pay: A Black-Box Audit of Provider-Side Token Inflation in LLM Services
Leilei Chen, Lan Zhang, Chen Tang et al.
A Scalable Trust Discovery Architecture for the Internet of Agents
Song Zhang, Jiankang Yao, Hongtao Li et al.