Say No to Freeloader: Protecting Intellectual Property of Your Deep Model

被引:0
|
作者
Wang, Lianyu [1 ]
Wang, Meng [2 ]
Fu, Huazhu [2 ]
Zhang, Daoqiang [1 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Artificial Intelligence, Key Lab Brain Machine Intelligence Technol, Minist Educ, Nanjing 211106, Peoples R China
[2] ASTAR, Agcy Sci Res & Technol, Inst High Performance Comp IHPC, Singapore 138632, Singapore
基金
中国国家自然科学基金;
关键词
Deep learning; deep model IP; domain transfer; WATERMARKING;
D O I
10.1109/TPAMI.2024.3450282
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Model intellectual property (IP) protection has gained attention due to the significance of safeguarding intellectual labor and computational resources. Ensuring IP safety for trainers and owners is critical, especially when ownership verification and applicability authorization are required. A notable approach involves preventing the transfer of well-trained models from authorized to unauthorized domains. We introduce a novel Compact Un-transferable Pyramid Isolation Domain (CUPI-Domain) which serves as a barrier against illegal transfers from authorized to unauthorized domains. Inspired by human transitive inference, the CUPI-Domain emphasizes distinctive style features of the authorized domain, leading to failure in recognizing irrelevant private style features on unauthorized domains. To this end, we propose CUPI-Domain generators, which select features from both authorized and CUPI-Domain as anchors. These generators fuse the style features and semantic features to create labeled, style-rich CUPI-Domain. Additionally, we design external Domain-Information Memory Banks (DIMB) for storing and updating labeled pyramid features to obtain stable domain class features and domain class-wise style features. Based on the proposed whole method, the novel style and discriminative loss functions are designed to effectively enhance the distinction in style and discriminative features between authorized and unauthorized domains. We offer two solutions for utilizing CUPI-Domain based on whether the unauthorized domain is known: target-specified CUPI-Domain and target-free CUPI-Domain. Comprehensive experiments on various public datasets demonstrate the effectiveness of our CUPI-Domain approach with different backbone models, providing an efficient solution for model intellectual property protection.
引用
收藏
页码:11073 / 11086
页数:14
相关论文
共 50 条
  • [41] Your Model Trains on My Data? Protecting Intellectual Property of Training Data via Membership Fingerprint Authentication
    Liu, Gaoyang
    Xu, Tianlong
    Ma, Xiaoqiang
    Wang, Chen
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1024 - 1037
  • [42] Protecting Intellectual Property of EEG-based Model with Watermarking
    Xu, Tianhua
    Zhong, Sheng-Hua
    Xiao, Zhijiao
    2023 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, ICME, 2023, : 37 - 42
  • [43] CHAL 17 - Biomedical nanotechnology: Patent trends and strategies for protecting your intellectual property
    Thiessen, Rose
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2009, 237 : 923 - 923
  • [44] Protecting the Intellectual Property of Deep Neural Networks with Watermarking: The Frequency Domain Approach
    Li, Meng
    Zhong, Qi
    Zhang, Leo Yu
    Du, Yajuan
    Zhang, Jun
    Xiang, Yong
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 402 - 409
  • [45] Deep Model Intellectual Property Protection via Deep Watermarking
    Zhang, Jie
    Chen, Dongdong
    Liao, Jing
    Zhang, Weiming
    Feng, Huamin
    Hua, Gang
    Yu, Nenghai
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2022, 44 (08) : 4005 - 4020
  • [46] Protecting Intellectual Property in Plants and Seeds
    Zullow, Keith A.
    Karmas, Raivo A.
    CEREAL FOODS WORLD, 2008, 53 (06) : 319 - 321
  • [47] Protecting intellectual property by guessing secrets
    Fernandez, M
    Soriano, M
    E-COMMERCE AND WEB TECHNOLOGIES, PROCEEDINGS, 2003, 2738 : 196 - 205
  • [48] Protecting Both Intellectual Property and Progress
    Frank, Emma
    BIOPHARM INTERNATIONAL, 2022, 35 (09) : 47 - 49
  • [49] Damages and injunctions in protecting intellectual property
    Sehankerman, M
    Scotchmer, S
    RAND JOURNAL OF ECONOMICS, 2001, 32 (01): : 199 - 220
  • [50] Protecting OEM's intellectual property
    2001, Miller Freedman Inc. (12):