Catch-Only-One: Model-Specific Non-Transferable Examples
Zihan Wang, Zhiyong Ma, Zhongkui Ma, Shuofeng Liu, Akide Liu, Derui Wang, Minhui Xue, Guangdong Bai
Recoding data in designated-model low-sensitivity directions to preserve its task utility and study reduced transfer to other models.
The problem
Released data may be reused with models other than the one intended by its provider. Catch-Only-One studies model-specific data utility through non-transferable examples (NTEs).
The method
The method recodes inputs in a designated model’s low-sensitivity subspace without retraining. Its analysis relates designated-model fidelity and cross-model degradation to properties of the models, including spectral misalignment. Different model identities alone are not a sufficient explanation of the effect.
Evidence and scope
The paper combines bounds under stated assumptions with experiments on vision and vision-language models, including adaptive reconstruction attacks. Fidelity and cross-model degradation are distinct from confidentiality: the reported results do not establish impossibility of every inversion attack.
Read the paper through the link above for the model conditions and evaluations. AdaLoc addresses the complementary question of controlling use from the model side.