2605.14291v1 May 14, 2026 cs.CR

보는 것이 곧 배우는 것은 아니다: 대규모 시각-언어 모델의 무단 미세 조정으로부터 멀티모달 데이터를 보호하는 방법

To See is Not to Learn: Protecting Multimodal Data from Unauthorized Fine-Tuning of Large Vision-Language Model

Zhen Tan
Zhen Tan
Citations: 100
h-index: 5
Huan Liu
Huan Liu
Citations: 23
h-index: 2
Dawei Li
Dawei Li
Citations: 10
h-index: 2
Zhiyuan Yu
Zhiyuan Yu
Citations: 82
h-index: 2
Chengshuai Zhao
Chengshuai Zhao
Arizona State University
Citations: 1,027
h-index: 10

대규모 시각-언어 모델(LVLM)의 빠른 발전은 멀티모달 웹 데이터에 대한 무단 스크래핑 및 학습으로 이어져 데이터 소유자에게 심각한 저작권 및 개인 정보 보호 위험을 초래하고 있습니다. 기존의 대응책인 머신 언러닝 및 워터마크는 사후적인 접근 방식으로, 지적 재산권 침해가 발생한 후에만 작동합니다. 본 연구에서는 데이터 소유자가 멀티모달 데이터를 무단 LVLM 미세 조정으로부터 적극적으로 보호할 수 있도록 MMGuard를 제안합니다. MMGuard는 인간에게 거의 감지되지 않는 노이즈를 주입하여 LVLM의 학습 역학을 적극적으로 활용함으로써 학습 불가능한 예제를 생성합니다. 이 노이즈는 학습 손실을 최소화하여 모델이 노이즈에 과적합되도록 만들고, 결과적으로 추론 시 노이즈가 없을 때 성능이 저하됩니다. 이 방어 체계를 더욱 강화하기 위해 MMGuard는 이론적 보장을 갖춘 교차 모드 바인딩 파괴를 도입하여 LVLM의 주의를 전략적으로 이동시켜 노이즈와 학습 목표 간의 가짜 상관관계를 강제합니다. 앙상블 학습 전략을 통해 교차 모델 간의 전이성을 향상시킨 MMGuard는 6개의 데이터 세트에 걸쳐 9개의 오픈 소스 LVLM에 대해 평가되었습니다. 종합적인 결과는 화이트박스, 그레이박스, 블랙박스 위협 모델 하에서 효과적이고 은밀하며 강력한 보호 기능을 제공하며, 적극적인 미세 조정 악용에 대한 메커니즘적 이점을 입증합니다.

Original Abstract

The rapid advancement of Large Vision-Language Models (LVLMs) is increasingly accompanied by unauthorized scraping and training on multimodal web data, posing severe copyright and privacy risks to data owners. Existing countermeasures, such as machine unlearning and watermarks, are inherent post-hoc approaches that act only after intellectual property infringement has already occurred. In this work, we propose MMGuard to empower data owners to proactively protect their multimodal data against unauthorized LVLM fine-tuning. MMGuard generates unlearnable examples by injecting human-imperceptible perturbations that actively exploit the learning dynamics of LVLMs. By minimizing the training loss, the perturbation creates an optimization shortcut, causing the model to overfit to the noise and thereby degrading downstream performance when the perturbation is absent during inference. To further strengthen this defense, MMGuard introduces a cross-modal binding disruption, strategically shifting LVLM attention to enforce a spurious correlation between the noise and the training target with theoretical guarantees. Enhanced by an ensemble learning strategy for cross-model transferability, MMGuard is evaluated against nine open-source LVLMs across six datasets. Our comprehensive results demonstrate effective, stealthy, and robust protection under white-box, gray-box, and black-box threat models, establishing a mechanistic advantage in proactively defending against aggressive fine-tuning exploitation.

1 Citations
0 Influential
5 Altmetric
26.0 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!