CoreLocker: Neuron-level Usage Control
Zihan Wang, Zhongkui Ma, Xinguo Feng, Ruoxi Sun, Hu Wang, Minhui Xue, Guangdong Bai
Model usage control by extracting selected influential weights as a key for restoring the model's original capability.
The problem
A model owner may distribute a reduced-utility model while reserving restoration of its original capability for authorised users. CoreLocker studies parameter-based control in this setting.
The method
Selected influential weights are extracted as an access key. The distributed model omits those weights; restoring the key restores the original parameters. Selection matters because some weights have a disproportionate effect on model outputs.
Evidence and scope
The work studies the relationship between extraction, degraded utility and authorised restoration. The intended deployment distinguishes access to the keyed model from access to the extracted weights. Security evaluation therefore depends on the adversary’s access and permitted recovery or adaptation attempts.
Use the original implementation linked above for the split and recovery workflow. AdaLoc extends the control question to model updates, while AIM studies behaviour modulation.
Citation
@inproceedings{wang2024corelocker,
title={CoreLocker: Neuron-level Usage Control},
author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Sun, Ruoxi and Wang, Hu and Xue, Minhui and Bai, Guangdong},
booktitle={2024 IEEE Symposium on Security and Privacy (SP)},
pages={222--222},
year={2024},
organization={IEEE Computer Society}
}