36
0

MUSE: Model-Agnostic Tabular Watermarking via Multi-Sample Selection

Main:10 Pages
8 Figures
Bibliography:3 Pages
5 Tables
Appendix:12 Pages
Abstract

We introduce MUSE, a watermarking algorithm for tabular generative models. Previous approaches typically leverage DDIM invertibility to watermark tabular diffusion models, but tabular diffusion models exhibit significantly poorer invertibility compared to other modalities, compromising performance. Simultaneously, tabular diffusion models require substantially less computation than other modalities, enabling a multi-sample selection approach to tabular generative model watermarking. MUSE embeds watermarks by generating multiple candidate samples and selecting one based on a specialized scoring function, without relying on model invertibility. Our theoretical analysis establishes the relationship between watermark detectability, candidate count, and dataset size, allowing precise calibration of watermarking strength. Extensive experiments demonstrate that MUSE achieves state-of-the-art watermark detectability and robustness against various attacks while maintaining data quality, and remains compatible with any tabular generative model supporting repeated sampling, effectively addressing key challenges in tabular data watermarking. Specifically, it reduces the distortion rates on fidelity metrics by 81-89%, while achieving a 1.0 TPR@0.1%FPR detection rate. Implementation of MUSE can be found atthis https URL.

View on arXiv
@article{fang2025_2505.24267,
  title={ MUSE: Model-Agnostic Tabular Watermarking via Multi-Sample Selection },
  author={ Liancheng Fang and Aiwei Liu and Henry Peng Zou and Yankai Chen and Hengrui Zhang and Zhongfen Deng and Philip S. Yu },
  journal={arXiv preprint arXiv:2505.24267},
  year={ 2025 }
}
Comments on this paper