Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring

02/13/2018
by   Yossi Adi, et al.
0

Deep Neural Networks have recently gained lots of success after enabling several breakthroughs in notoriously challenging problems. Training these networks is computationally expensive and requires vast amounts of training data. Selling such pre-trained models can, therefore, be a lucrative business model. Unfortunately, once the models are sold they can be easily copied and redistributed. To avoid this, a tracking mechanism to identify models as the intellectual property of a particular vendor is necessary. In this work, we present an approach for watermarking Deep Neural Networks in a black-box way. Our scheme works for general classification tasks and can easily be combined with current learning algorithms. We show experimentally that such a watermark has no noticeable impact on the primary task that the model is designed for. Moreover, we evaluate the robustness of our proposal against a multitude of practical attacks.

READ FULL TEXT
research
03/05/2019

DeepStego: Protecting Intellectual Property of Deep Neural Networks by Steganography

Deep Neural Networks (DNNs) has shown great success in various challengi...
research
10/31/2019

Robust and Undetectable White-Box Watermarks for Deep Neural Networks

Training deep neural networks (DNN) is expensive in terms of computation...
research
08/09/2019

DeepCleanse: A Black-box Input SanitizationFramework Against Backdoor Attacks on DeepNeural Networks

As Machine Learning, especially Deep Learning, has been increasingly use...
research
06/08/2023

Detecting Neural Trojans Through Merkle Trees

Deep neural networks are utilized in a growing number of industries. Muc...
research
03/19/2023

A model is worth tens of thousands of examples

Traditional signal processing methods relying on mathematical data gener...
research
08/10/2018

Out of the Black Box: Properties of deep neural networks and their applications

Deep neural networks are powerful machine learning approaches that have ...
research
08/05/2022

FBI: Fingerprinting models with Benign Inputs

Recent advances in the fingerprinting of deep neural networks detect ins...

Please sign up or login with your details

Forgot password? Click here to reset