跳到主要导航 跳到搜索 跳到主要内容

DeepTrace: A Secure Fingerprinting Framework for Intellectual Property Protection of Deep Neural Networks

  • Runhao Wang
  • , Jiexiang Kang
  • , Wei Yin
  • , Hui Wang
  • , Haiying Sun
  • , Xiaohong Chen
  • , Zhongjie Gao
  • , Shuning Wang
  • , Jing Liu*
  • *此作品的通讯作者
  • East China Normal University
  • China Aeronautical Radio Electronics Research Institute

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Deep Neural Networks (DNN) has gained great success in solving several challenging problems in recent years. It is well known that training a DNN model from scratch requires a lot of data and computational resources. However, using a pre-trained model directly or using it to initialize weights cost less time and often gets better results. Therefore, well pre-trained DNN models are valuable intellectual property that we should protect. In this work, we propose DeepTrace, a framework for model owners to secretly fingerprinting the target DNN model using a special trigger set and verifying from outputs. An embedded fingerprint can be extracted to uniquely identify the information of model owner and authorized users. Our framework benefits from both white-box and black-box verification, which makes it useful whether we know the model details or not. We evaluate the performance of DeepTrace on two different datasets, with different DNN architectures. Our experiment shows that, with the advantages of combining white-box and black-box verification, our framework has very little effect on model accuracy, and is robust against different model modifications. It also consumes very little computing resources when extracting fingerprint.

源语言英语
主期刊名Proceedings - 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021
编辑Liang Zhao, Neeraj Kumar, Robert C. Hsu, Deqing Zou
出版商Institute of Electrical and Electronics Engineers Inc.
188-195
页数8
ISBN(电子版)9781665416580
DOI
出版状态已出版 - 2021
活动20th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021 - Shenyang, 中国
期限: 20 10月 202122 10月 2021

出版系列

姓名Proceedings - 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021

会议

会议20th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2021
国家/地区中国
Shenyang
时期20/10/2122/10/21

指纹

探究 'DeepTrace: A Secure Fingerprinting Framework for Intellectual Property Protection of Deep Neural Networks' 的科研主题。它们共同构成独一无二的指纹。

引用此