Researchers have developed a new method called SWAP (Sequential Watermarking for Soft Prompts) to protect the copyright of soft prompts used with large vision-language models like CLIP. Existing auditing techniques are ineffective because they either introduce false positives or fail to embed functional triggers without harming the model's primary task. SWAP embeds watermarks in a distinct, more complex space by encoding them through a specific order of out-of-distribution classes, inspired by CLIP's zero-shot capabilities. This approach ensures the original prediction labels remain unchanged, making it less detrimental to the model's performance. Extensive experiments have shown SWAP to be effective, harmless, and robust against various attacks. AI
IMPACT Introduces a novel technique for copyright protection in AI models, potentially impacting the development and deployment of proprietary soft prompts.
RANK_REASON This is a research paper detailing a new method for auditing soft prompts. [lever_c_demoted from research: ic=1 ai=1.0]
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →