Identification for Deep Neural Network: Simply Adjusting Few Weights!
Yingjie Lao, Peng Yang, Weijie Zhao, Ping Li
摘要
Through the development of powerful algorithms and design tools, deep neural networks (DNNs) have recently approached or even surpassed human-level performance in many real-world applications. Nowadays, since a product-level DNN modeling requires a large amount of training data and expensive computing resources and thus DNN models are considered as valuable data, protecting the intellectual property (IP) of DNN builders becomes an important problem in the security domain. In this paper, we propose a novel watermarking approach that only requires adjusting a few weights, as opposed to prior works that embed watermarks via end-to-end training. The protected model with tiny parameter modifications can output pre-specified labels with carefully selected key samples as inputs, which serves as a strong proof of ownership. Besides, our methodology can be naturally extended to identification, i.e., embedding unique watermarks to identify different users. Watermark embedding is achieved by modifying a very small subset of parameters, guaranteeing a high fidelity while dramatically reducing the computational overhead. The experimental results demonstrate that the proposed algorithm can embed key samples with a high success rate, while well preserving the original functionality of the target model. We show that the proposed method is robust against various transformation attacks.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper4
- Defending Backdoor Attacks on Vision Transformer via Patch ProcessingKhoa D. Doan, Yingjie Lao, Peng Yang, Ping LiAAAI 2023 · 被引用 33 次
- Free Fine-tuning: A Plug-and-Play Watermarking Scheme for Deep Neural NetworksRun Wang, Jixing Ren, Boheng Li, Tianyi She 等ACM MM 2023 · 被引用 20 次
- DeepEclipse: How to Break White-Box DNN-Watermarking SchemesAlessandro Pegoraro, Carlotta Segna, Kavita Kumari, Ahmad-Reza SadeghiUSENIX Security 2024 · 被引用 11 次
- Integrity Authentication in Tree ModelsWeijie Zhao, Yingjie Lao, Ping LiKDD 2022 · 被引用 3 次
相关 Paper
- Watermarking Deep Neural Networks with Greedy ResidualsHanwen Liu, Zhenyu Weng, Yuesheng ZhuICML 2021 · 被引用 69 次
- Robust Watermarking for Deep Neural Networks via Bi-level OptimizationPeng Yang, Yingjie Lao, Ping LiICCV 2021 · 被引用 67 次
- DeepAuth: A DNN Authentication Framework by Model-Unique and Fragile Signature EmbeddingYingjie Lao, Weijie Zhao, Peng Yang, Ping LiAAAI 2022 · 被引用 34 次
- Resource Efficient Deep Learning Hardware Watermarks with Signature AlignmentJoseph Clements, Yingjie LaoAAAI 2024 · 被引用 3 次
- Towards Robust Model Watermark via Reducing Parametric VulnerabilityGuanhao Gan, Yiming Li, Dongxian Wu, Shu-Tao XiaICCV 2023 · 被引用 18 次
