Effective Ambiguity Attack Against Passport-based DNN Intellectual Property Protection Schemes through Fully Connected Layer Substitution
Yiming Chen, Jinyu Tian, Xiangyu Chen, Jiantao Zhou
Abstract
Since training a deep neural network (DNN) is costly, the well-trained deep models can be regarded as valuable intellectual property (IP) assets. The IP protection associated with deep models has been receiving increasing attentions in recent years. Passport-based method, which replaces normalization layers with passport layers, has been one of the few protection solutions that are claimed to be secure against advanced attacks. In this work, we tackle the issue of evaluating the security of passport-based IP protection methods. We propose a novel and effective ambiguity attack against passport-based method, capable of successfully forging multiple valid passports with a small training dataset. This is accomplished by inserting a specially designed accessory block ahead of the passport parameters. Using less than 10% of training data, with the forged passport, the model exhibits almost indistinguishable performance difference (less than 2%) compared with that of the authorized passport. In addition, it is shown that our attack strategy can be readily generalized to attack other IP protection methods based on watermark embedding. Directions for potential remedy solutions are also given.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4bcb87b0-7d12-40e6-a4fb-dd1825c392a1Cited by top-tier papers2
- False Claims against Model Ownership ResolutionJian Liu, Rui Zhang, Sebastian Szyller, Kui Ren et al.USENIX Security 2024 · 22 citations
- Steganographic Passport: An Owner and User Verifiable Credential for Deep Model IP Protection Without RetrainingQi Cui, Ruohan Meng, Chaohui Xu, Chip-Hong ChangCVPR 2024
Builds on6
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Model Watermarking for Image Processing NetworksJie Zhang, Dongdong Chen, Jing Liao, Han Fang et al.AAAI 2020 · 160 citations
- DAWN: Dynamic Adversarial Watermarking of Neural NetworksSebastian Szyller, Buse Gul Atli, Samuel Marchal, N. AsokanACM MM 2021 · 133 citations
- Passport-aware Normalization for Deep Model ProtectionJie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang et al.NeurIPS 2020 · 108 citations
- Watermarking Deep Neural Networks with Greedy ResidualsHanwen Liu, Zhenyu Weng, Yuesheng ZhuICML 2021 · 69 citations
Related papers
- Trapdoor Normalization with Irreversible Ownership VerificationHanwen Liu, Zhenyu Weng, Yuesheng Zhu, Yadong MuICML 2023 · 9 citations
- Identification for Deep Neural Network: Simply Adjusting Few Weights!Yingjie Lao, Peng Yang, Weijie Zhao, Ping LiICDE 2022 · 19 citations
- Rethinking the Vulnerability of DNN Watermarking: Are Watermarks Robust against Naturalness-aware Perturbations?Run Wang, Haoxuan Li, Lingzhou Mu, Jixing Ren et al.ACM MM 2022 · 9 citations
- ActiveDaemon: Unconscious DNN Dormancy and Waking Up via User-specific Invisible TokenGe Ren, Gaolei Li, Shenghong Li, Libo Chen et al.NDSS 2024
- MEA-Defender: A Robust Watermark against Model Extraction AttackPeizhuo Lv, Hualong Ma, Kai Chen, Jiachen Zhou et al.S&P 2024 · 22 citations
