NaturalFinger: Generating Natural Fingerprint with Generative Adversarial Networks

05/29/2023
by   Kang Yang, et al.
0

Deep neural network (DNN) models have become a critical asset of the model owner as training them requires a large amount of resource (i.e. labeled data). Therefore, many fingerprinting schemes have been proposed to safeguard the intellectual property (IP) of the model owner against model extraction and illegal redistribution. However, previous schemes adopt unnatural images as the fingerprint, such as adversarial examples and noisy images, which can be easily perceived and rejected by the adversary. In this paper, we propose NaturalFinger which generates natural fingerprint with generative adversarial networks (GANs). Besides, our proposed NaturalFinger fingerprints the decision difference areas rather than the decision boundary, which is more robust. The application of GAN not only allows us to generate more imperceptible samples, but also enables us to generate unrestricted samples to explore the decision boundary.To demonstrate the effectiveness of our fingerprint approach, we evaluate our approach against four model modification attacks including adversarial training and two model extraction attacks. Experiments show that our approach achieves 0.91 ARUC value on the FingerBench dataset (154 models), exceeding the optimal baseline (MetaV) over 17%.

READ FULL TEXT

page 2

page 6

page 7

research
01/06/2021

Model Extraction and Defenses on Generative Adversarial Networks

Model extraction attacks aim to duplicate a machine learning model throu...
research
10/07/2021

Fingerprinting Multi-exit Deep Neural Network Models via Inference Time

Transforming large deep neural network (DNN) models into the multi-exit ...
research
06/08/2023

Ownership Protection of Generative Adversarial Networks

Generative adversarial networks (GANs) have shown remarkable success in ...
research
09/17/2020

ExGAN: Adversarial Generation of Extreme Samples

Mitigating the risk arising from extreme events is a fundamental goal wi...
research
06/21/2021

FDeblur-GAN: Fingerprint Deblurring using Generative Adversarial Network

While working with fingerprint images acquired from crime scenes, mobile...
research
05/21/2017

DeepMasterPrint: Generating Fingerprints for Presentation Attacks

We present two related methods for creating MasterPrints, synthetic fing...
research
12/25/2018

Finger-GAN: Generating Realistic Fingerprint Images Using Connectivity Imposed GAN

Generating realistic biometric images has been an interesting and, at th...

Please sign up or login with your details

Forgot password? Click here to reset