Active intellectual property protection for deep neural networks through stealthy backdoor and users' identities authentication

被引:9
|
作者
Xue, Mingfu [1 ]
Sun, Shichang [1 ]
Zhang, Yushu [1 ]
Wang, Jian [1 ]
Liu, Weiqiang [2 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing, Peoples R China
[2] Nanjing Univ Aeronaut & Astronaut, Coll Elect & Informat Engn, Nanjing, Peoples R China
基金
中国国家自然科学基金;
关键词
Deep neural networks; Intellectual property protection; Backdoor; Users' fingerprints authentication; Ownership verification;
D O I
10.1007/s10489-022-03339-0
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, the intellectual properties (IP) protection of deep neural networks (DNN) has attracted serious concerns. A number of DNN copyright protection methods have been proposed. However, most of the existing DNN watermarking methods can only verify the ownership of the model after the piracy occurs, which cannot actively prevent the occurrence of the piracy and do not support users' identities management, thus can not satisfy the requirements of commercial DNN copyright management. In addition, the query modification attack which was proposed recently can invalidate most of the existing backdoor-based DNN watermarking methods. In this paper, we propose an active intellectual properties protection technique for DNN models via stealthy backdoor and users' identities authentication. For the first time, we use a set of clean images (as the watermark key samples) to embed an additional class into the DNN for ownership verification, and use the image steganography to embed users' identity information into these watermark key images. Each user will be assigned with a unique identity image for identity authentication and authorization control. Since the backdoor instances are clean images outside the dataset, the backdoor trigger is visually imperceptible and concealed. In addition, we embed the watermark by exploiting an additional class outside the main tasks, which establishes a strong connection for watermark key samples and the corresponding label. As a result, the proposed method is concealed, robust, and can resist common attacks and query modification attack. Experimental results demonstrate that, the proposed method can obtain 100% watermark accuracy and 100% fingerprint authentication success rate on Fashion-MNIST and CIFAR-10 datasets. In addition, the proposed method is demonstrated to be robust against the model fine-tuning attack, model pruning attack, and query modification attack. Compared with three existing DNN watermarking methods, the proposed method has better performance on watermark accuracy and robustness against the query modification attack.
引用
收藏
页码:16497 / 16511
页数:15
相关论文
共 23 条
  • [11] Intellectual Property Protection of Deep Neural Network Models Based on Watermarking Technology
    Jin, Biao
    Lin, Xiang
    Xiong, Jinbo
    You, Weijing
    Li, Xuan
    Yao, Zhiqiang
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2024, 61 (10): : 2587 - 2606
  • [12] Protecting the Intellectual Property of Deep Neural Networks with Watermarking: The Frequency Domain Approach
    Li, Meng
    Zhong, Qi
    Zhang, Leo Yu
    Du, Yajuan
    Zhang, Jun
    Xiang, Yong
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 402 - 409
  • [13] Chaotic Weights: A Novel Approach to Protect Intellectual Property of Deep Neural Networks
    Lin, Ning
    Chen, Xiaoming
    Lu, Hang
    Li, Xiaowei
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2021, 40 (07) : 1327 - 1339
  • [14] IPGuard: Protecting Intellectual Property of Deep Neural Networks via Fingerprinting the Classification Boundary
    Cao, Xiaoyu
    Jia, Jinyuan
    Gong, Neil Zhenqiang
    ASIA CCS'21: PROCEEDINGS OF THE 2021 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 14 - 25
  • [15] Invisible and Multi-triggers Backdoor Attack Approach on Deep Neural Networks through Frequency Domain
    Sun, Fengxue
    Pei, Bei
    Chen, Guangyong
    2024 9TH INTERNATIONAL CONFERENCE ON SIGNAL AND IMAGE PROCESSING, ICSIP, 2024, : 707 - 711
  • [16] Steganography of Digital Watermark Based on Artificial Neural Networks in Image Communication and Intellectual Property Protection
    Chong Yu
    Neural Processing Letters, 2016, 44 : 307 - 316
  • [17] Steganography of Digital Watermark Based on Artificial Neural Networks in Image Communication and Intellectual Property Protection
    Yu, Chong
    NEURAL PROCESSING LETTERS, 2016, 44 (02) : 307 - 316
  • [18] BIOMETRIC HUMAN AUTHENTICATION SYSTEM THROUGH SPEECH USING DEEP NEURAL NETWORKS (DNN)
    Mamyrbayev, O.
    Akhmediyarova, A.
    Kydyrbekova, A.
    Mekebayev, N. O.
    Zhumazhanov, B.
    BULLETIN OF THE NATIONAL ACADEMY OF SCIENCES OF THE REPUBLIC OF KAZAKHSTAN, 2020, (05): : 6 - 15
  • [19] Protecting the Intellectual Property of Binary Deep Neural Networks With Efficient Spintronic-Based Hardware Obfuscation
    Mohseni, Alireza
    Moaiyeri, Mohammad Hossein
    Amirany, Abdolah
    Rezayati, Mohammad Hadi
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS I-REGULAR PAPERS, 2024, 71 (07) : 3146 - 3156
  • [20] Enumeration and Identification of Active Users for Grant-Free NOMA Using Deep Neural Networks
    Khan, Muhammad Usman
    Paolini, Enrico
    Chiani, Marco
    IEEE ACCESS, 2022, 10 : 125616 - 125625