Passport-aware Normalization for Deep Model Protection
Jie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang, Gang Hua, Nenghai Yu
摘要
Despite tremendous success in many application scenarios, deep learning faces serious intellectual property (IP) infringement threats. Considering the cost of designing and training a good model, infringements will significantly infringe the interests of the original model owner. Recently, many impressive works have emerged for deep model IP protection. However, they either are vulnerable to ambiguity attacks, or require changes in the target network structure by replacing its original normalization layers and hence cause significant performance drops. To this end, we propose a new passport-aware normalization formulation, which is generally applicable to most existing normalization layers and only needs to add another passport-aware branch for IP protection. This new branch is jointly trained with the target model but discarded in the inference stage. Therefore it causes no structure change in the target model. Only when the model IP is suspected to be stolen by someone, the private passport-aware branch is added back for ownership verification. Through extensive experiments, we verify its effectiveness in both image and 3D point recognition models. It is demonstrated to be robust not only to common attack techniques like fine-tuning and model compression, but also to ambiguity attacks. By further combining it with trigger-set based methods, both black-box and white-box verification can be achieved for enhanced security of deep learning models deployed in real systems. Code can be found at this https URL.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper19
- Defending against Model Stealing via Verifying Embedded External FeaturesYiming Li, Linghui Zhu, Xiaojun Jia, Yong Jiang 等AAAI 2022 · 被引用 87 次
- Undistillable: Making A Nasty Teacher That CANNOT teach studentsHaoyu Ma, Tianlong Chen, Ting-Kuei Hu, Chenyu You 等ICLR 2021 · 被引用 58 次
- Are You Stealing My Model? Sample Correlation for Fingerprinting Deep Neural NetworksJiyang Guan, Jian Liang, Ran HeNeurIPS 2022 · 被引用 57 次
- Analyzing the Confidentiality of Undistillable Teachers in Knowledge DistillationSouvik Kundu, Qirui Sun, Yao Fu, Massoud Pedram 等NeurIPS 2021 · 被引用 35 次
- You are caught stealing my winning lottery ticket! Making a lottery ticket claim its ownershipXuxi Chen, Tianlong Chen, Zhenyu Zhang, Zhangyang WangNeurIPS 2021 · 被引用 34 次
它引用的顶会 Paper2
相关 Paper
- Effective Ambiguity Attack Against Passport-based DNN Intellectual Property Protection Schemes through Fully Connected Layer SubstitutionYiming Chen, Jinyu Tian, Xiangyu Chen, Jiantao ZhouCVPR 2023
- Trapdoor Normalization with Irreversible Ownership VerificationHanwen Liu, Zhenyu Weng, Yuesheng Zhu, Yadong MuICML 2023 · 被引用 9 次
- Steganographic Passport: An Owner and User Verifiable Credential for Deep Model IP Protection Without RetrainingQi Cui, Ruohan Meng, Chaohui Xu, Chip-Hong ChangCVPR 2024
- Deep Neural Network Watermarking against Model Extraction AttackJingxuan Tan, Nan Zhong, Zhenxing Qian, Xinpeng Zhang 等ACM MM 2023 · 被引用 34 次
- DeepEclipse: How to Break White-Box DNN-Watermarking SchemesAlessandro Pegoraro, Carlotta Segna, Kavita Kumari, Ahmad-Reza SadeghiUSENIX Security 2024 · 被引用 11 次
