Passport-aware Normalization for Deep Model Protection

10/29/2020
by   Jie Zhang, et al.
0

Despite tremendous success in many application scenarios, deep learning faces serious intellectual property (IP) infringement threats. Considering the cost of designing and training a good model, infringements will significantly infringe the interests of the original model owner. Recently, many impressive works have emerged for deep model IP protection. However, they either are vulnerable to ambiguity attacks, or require changes in the target network structure by replacing its original normalization layers and hence cause significant performance drops. To this end, we propose a new passport-aware normalization formulation, which is generally applicable to most existing normalization layers and only needs to add another passport-aware branch for IP protection. This new branch is jointly trained with the target model but discarded in the inference stage. Therefore it causes no structure change in the target model. Only when the model IP is suspected to be stolen by someone, the private passport-aware branch is added back for ownership verification. Through extensive experiments, we verify its effectiveness in both image and 3D point recognition models. It is demonstrated to be robust not only to common attack techniques like fine-tuning and model compression, but also to ambiguity attacks. By further combining it with trigger-set based methods, both black-box and white-box verification can be achieved for enhanced security of deep learning models deployed in real systems. Code can be found at https://github.com/ZJZAC/Passport-aware-Normalization.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/30/2021

You are caught stealing my winning lottery ticket! Making a lottery ticket claim its ownership

Despite tremendous success in many application scenarios, the training a...
research
03/21/2023

Effective Ambiguity Attack Against Passport-based DNN Intellectual Property Protection Schemes through Fully Connected Layer Substitution

Since training a deep neural network (DNN) is costly, the well-trained d...
research
04/02/2018

DeepSigns: A Generic Watermarking Framework for IP Protection of Deep Learning Models

This paper proposes DeepSigns, a novel end-to-end framework for systemat...
research
10/03/2022

An Embarrassingly Simple Approach for Intellectual Property Rights Protection on Recurrent Neural Networks

Capitalise on deep learning models, offering Natural Language Processing...
research
03/08/2021

Deep Model Intellectual Property Protection via Deep Watermarking

Despite the tremendous success, deep neural networks are exposed to seri...
research
03/20/2023

Model Barrier: A Compact Un-Transferable Isolation Domain for Model Intellectual Property Protection

As scientific and technological advancements result from human intellect...
research
12/10/2021

Protecting Your NLG Models with Semantic and Robust Watermarks

Natural language generation (NLG) applications have gained great popular...

Please sign up or login with your details

Forgot password? Click here to reset