A DNN Fingerprint for Non-Repudiable Model Ownership Identification and Piracy Detection

被引:6
|
作者
Zheng, Yue [1 ]
Wang, Si [1 ]
Chang, Chip-Hong [1 ]
机构
[1] Nanyang Technol Univ, Sch Elect & Elect Engn, Singapore 639798, Singapore
基金
新加坡国家研究基金会;
关键词
Feature extraction; Watermarking; Training; Data models; Convolution; Computational modeling; Predictive models; DNN IP protection; fingerprinting; random projection; cross application; ownership; DEVICE HASH;
D O I
10.1109/TIFS.2022.3198267
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A high-performance Deep Neural Network (DNN) model is a valuable intellectual property (IP) since designing and training such a model from scratch is very costly. Model transfer learning, compression and retraining are commonly used by pirates to evade detection or even redeploy the pirated models for new applications without compromising performance. This paper presents a novel non-intrusive DNN IP fingerprinting method that can detect pirated models and provide a non-repudiable and irrevocable ownership proof simultaneously. The fingerprint is derived from projecting a subset of front-layer weights onto a model owner identity defined random space to enable a distinguisher to differentiate pirated models that are used in the same application or retrained for a different task from originally designed DNN models. The proposed method generates compact and irrevocable fingerprints against model IP misappropriation and ownership fraud. It requires no retraining and makes no modification to the original model. The proposed fingerprinting method is evaluated on nine original DNN models trained on CIFAR-10, CIFAR-100, and ImageNet-10. It is demonstrated to have the highest discriminative power among existing fingerprinting methods in detecting pirated models deployed for the same and different applications, and fraudulent model IP ownership claims.
引用
收藏
页码:2977 / 2989
页数:13
相关论文
共 5 条
  • [1] A TinyML approach to non-repudiable anomaly detection in extreme industrial environments
    Antonini, Mattia
    Pincheira, Miguel
    Vecchio, Massimo
    Antonelli, Fabio
    [J]. PROCEEDINGS OF 2022 IEEE INTERNATIONAL WORKSHOP ON METROLOGY FOR INDUSTRY 4.0 & IOT (IEEE METROIND4.0&IOT), 2022, : 397 - 402
  • [2] Mobile Partial Identity Management: The Non-repudiable Minimal Mobile Identity Model
    Samadani, Mohammad Hasan
    Shajari, Mehdi
    [J]. FUTURE GENERATION INFORMATION TECHNOLOGY, 2010, 6485 : 439 - 449
  • [3] A robust DNN model for text-independent speaker identification using non-speaker embeddings in diverse data conditions
    Shome, Nirupam
    Saritha, Banala
    Kashyap, Richik
    Laskar, Rabul Hussain
    [J]. NEURAL COMPUTING & APPLICATIONS, 2023, 35 (26): : 18933 - 18947
  • [4] A robust DNN model for text-independent speaker identification using non-speaker embeddings in diverse data conditions
    Nirupam Shome
    Banala Saritha
    Richik Kashyap
    Rabul Hussain Laskar
    [J]. Neural Computing and Applications, 2023, 35 : 18933 - 18947
  • [5] STRUCTURE DETECTION AND MODEL VALIDITY TESTS IN THE IDENTIFICATION OF NON-LINEAR SYSTEMS
    BILLINGS, SA
    VOON, WSF
    [J]. IEE PROCEEDINGS-D CONTROL THEORY AND APPLICATIONS, 1983, 130 (04): : 193 - 199