Rethinking Deep Neural Network Ownership Verification: Embedding Passports to Defeat Ambiguity Attacks

09/16/2019
by   Lixin Fan, et al.
4

With the rapid development of deep neural networks (DNN), there emerges an urgent need to protect the trained DNN models from being illegally copied, redistributed, or abused without respecting the intellectual properties of legitimate owners. Following recent progresses along this line, we investigate a number of watermark-based DNN ownership verification methods in the face of ambiguity attacks, which aim to cast doubts on ownership verification by forging counterfeit watermarks. It is shown that ambiguity attacks pose serious challenges to existing DNN watermarking methods. As remedies to the above-mentioned loophole, this paper proposes novel passport-based DNN ownership verification schemes which are both robust to network modifications and resilient to ambiguity attacks. The gist of embedding digital passports is to design and train DNN models in a way such that, the DNN model performance of an original task will be significantly deteriorated due to forged passports. In other words genuine passports are not only verified by looking for predefined signatures, but also reasserted by the unyielding DNN model performances. Extensive experimental results justify the effectiveness of the proposed passport-based DNN ownership verification schemes. Code and models are available at https://github.com/kamwoh/DeepIPR

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/19/2019

A novel method for identifying the deep neural network model with the Serial Number

Deep neural network (DNN) with the state of art performance has emerged ...
research
08/06/2019

Refactoring Neural Networks for Verification

Deep neural networks (DNN) are growing in capability and applicability. ...
research
08/11/2021

SoK: How Robust is Image Classification Deep Neural Network Watermarking? (Extended Version)

Deep Neural Network (DNN) watermarking is a method for provenance verifi...
research
08/23/2023

RemovalNet: DNN Fingerprint Removal Attacks

With the performance of deep neural networks (DNNs) remarkably improving...
research
05/26/2021

DNNV: A Framework for Deep Neural Network Verification

Despite the large number of sophisticated deep neural network (DNN) veri...
research
09/27/2021

FedIPR: Ownership Verification for Federated Deep Neural Network Models

Federated learning models must be protected against plagiarism since the...
research
10/30/2021

You are caught stealing my winning lottery ticket! Making a lottery ticket claim its ownership

Despite tremendous success in many application scenarios, the training a...

Please sign up or login with your details

Forgot password? Click here to reset