Effective Ambiguity Attack Against Passport-based DNN Intellectual Property Protection Schemes through Fully Connected Layer Substitution

03/21/2023
by   Yiming Chen, et al.
0

Since training a deep neural network (DNN) is costly, the well-trained deep models can be regarded as valuable intellectual property (IP) assets. The IP protection associated with deep models has been receiving increasing attentions in recent years. Passport-based method, which replaces normalization layers with passport layers, has been one of the few protection solutions that are claimed to be secure against advanced attacks. In this work, we tackle the issue of evaluating the security of passport-based IP protection methods. We propose a novel and effective ambiguity attack against passport-based method, capable of successfully forging multiple valid passports with a small training dataset. This is accomplished by inserting a specially designed accessory block ahead of the passport parameters. Using less than 10 the forged passport, the model exhibits almost indistinguishable performance difference (less than 2 addition, it is shown that our attack strategy can be readily generalized to attack other IP protection methods based on watermark embedding. Directions for potential remedy solutions are also given.

READ FULL TEXT
research
11/27/2020

DNN Intellectual Property Protection: Taxonomy, Methods, Attack Resistance, and Evaluations

The training and creation of deep learning model is usually costly, thus...
research
04/28/2023

NNSplitter: An Active Defense Solution to DNN Model via Automated Weight Obfuscation

As a type of valuable intellectual property (IP), deep neural network (D...
research
10/29/2020

Passport-aware Normalization for Deep Model Protection

Despite tremendous success in many application scenarios, deep learning ...
research
03/20/2023

Model Barrier: A Compact Un-Transferable Isolation Domain for Model Intellectual Property Protection

As scientific and technological advancements result from human intellect...
research
06/11/2019

Evolutionary Trigger Set Generation for DNN Black-Box Watermarking

The commercialization of deep learning creates a compelling need for int...
research
10/14/2022

InFIP: An Explainable DNN Intellectual Property Protection Method based on Intrinsic Features

Intellectual property (IP) protection for Deep Neural Networks (DNNs) ha...
research
08/05/2021

Exploring Structure Consistency for Deep Model Watermarking

The intellectual property (IP) of Deep neural networks (DNNs) can be eas...

Please sign up or login with your details

Forgot password? Click here to reset