House of Cans: Covert Transmission of Internal Datasets via Capacity-Aware Neuron Steganography
Xudong Pan, Shengyao Zhang, Mi Zhang, Yifan Yan, Min Yang
Abstract
In this paper, we present a capacity-aware neuron steganography scheme (i.e., Cans ) to covertly transmit multiple private machine learning (ML) datasets via a scheduled-to-publish deep neural network (DNN) as the carrier model . Unlike existing steganography schemes which treat the DNN parameters as bit strings, Cans for the first time exploits the learning capacity of the carrier model via a novel parameter sharing mechanism. Extensive evaluation shows, Cans is the first working scheme which can covertly transmit over 10000 real-world data samples within a carrier model which has 220 × less parameters than the total size of the stolen data, and simultaneously transmit multiple heterogeneous datasets within a single carrier model, under a trivial distortion rate ( < 10 − 5 ) and with almost no utility loss on the carrier model ( < 1% ). Besides, Cans implements by-design redundancy to be resilient against common post-processing techniques on the carrier model before the publishing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6babb1bd-c60c-4fb0-b9df-c2dcbf3769b7Builds on14
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
Related papers
- Steganography of Steganographic NetworksGuobiao Li, Sheng Li, Meiling Li, Xinpeng Zhang et al.AAAI 2023 · 28 citations
- Purified and Unified Steganographic NetworkGuobiao Li, Sheng Li, Zicong Luo, Zhenxing Qian et al.CVPR 2024
- Large-Capacity and Flexible Video Steganography via Invertible Neural NetworkChong Mou, Youmin Xu, Jiechong Song, Chen Zhao et al.CVPR 2023
- ClearStamp: A Human-Visible and Robust Model-Ownership Proof based on Transposed Model TrainingTorsten Krauß, Jasper Stang, Alexandra DmitrienkoUSENIX Security 2024 · 9 citations
- Hiding Images in Deep Probabilistic ModelsHaoyu Chen, Linqi Song, Zhenxing Qian, Xinpeng Zhang et al.NeurIPS 2022 · 20 citations
