A novel method for identifying the deep neural network model with the Serial Number

11/19/2019
by   XiangRui Xu, et al.
25

Deep neural network (DNN) with the state of art performance has emerged as a viable and lucrative business service. However, those impressive performances require a large number of computational resources, which comes at a high cost for the model creators. The necessity for protecting DNN models from illegal reproducing and distribution appears salient now. Recently, trigger-set watermarking, breaking the white-box restriction, relying on adversarial training pre-defined (incorrect) labels for crafted inputs, and subsequently using them to verify the model authenticity, has been the main topic of DNN ownership verification. While these methods have successfully demonstrated robustness against removal attacks, few are effective against the tampering attacks from competitors forging the fake watermarks and dogging in the manager. In this paper, we put forth a new framework of the trigger-set watermark by embedding a unique Serial Number (relatedness less original labels) to the deep neural network for model ownership identification, which is both robust to model pruning and resist to tampering attacks. Experiment results demonstrate that the DNN Serial Number only incurs slight accuracy degradation of the original performance and is valid for ownership verification.

READ FULL TEXT

page 1

page 2

page 3

page 4

page 5

page 7

research
02/12/2022

TATTOOED: A Robust Deep Neural Network Watermarking Scheme based on Spread-Spectrum Channel Coding

The proliferation of deep learning applications in several areas has led...
research
09/16/2019

Rethinking Deep Neural Network Ownership Verification: Embedding Passports to Defeat Ambiguity Attacks

With the rapid development of deep neural networks (DNN), there emerges ...
research
08/11/2021

SoK: How Robust is Image Classification Deep Neural Network Watermarking? (Extended Version)

Deep Neural Network (DNN) watermarking is a method for provenance verifi...
research
06/02/2022

FACM: Correct the Output of Deep Neural Network with Middle Layers Features against Adversarial Samples

In the strong adversarial attacks against deep neural network (DNN), the...
research
10/27/2022

DICTION: DynamIC robusT whIte bOx watermarkiNg scheme

Deep neural network (DNN) watermarking is a suitable method for protecti...
research
10/07/2021

Fingerprinting Multi-exit Deep Neural Network Models via Inference Time

Transforming large deep neural network (DNN) models into the multi-exit ...
research
05/23/2023

Leveraging Uncertainty Quantification for Picking Robust First Break Times

In seismic exploration, the selection of first break times is a crucial ...

Please sign up or login with your details

Forgot password? Click here to reset