A Protection Method of Trained CNN Model Using Feature Maps Transformed With Secret Key From Unauthorized Access

09/01/2021
by   MaungMaung AprilPyone, et al.
0

In this paper, we propose a model protection method for convolutional neural networks (CNNs) with a secret key so that authorized users get a high classification accuracy, and unauthorized users get a low classification accuracy. The proposed method applies a block-wise transformation with a secret key to feature maps in the network. Conventional key-based model protection methods cannot maintain a high accuracy when a large key space is selected. In contrast, the proposed method not only maintains almost the same accuracy as non-protected accuracy, but also has a larger key space. Experiments were carried out on the CIFAR-10 dataset, and results show that the proposed model protection method outperformed the previous key-based model protection methods in terms of classification accuracy, key space, and robustness against key estimation attacks and fine-tuning attacks.

READ FULL TEXT
research
08/06/2020

Training DNN Model with Secret Key for Model Protection

In this paper, we propose a model protection method by using block-wise ...
research
04/09/2021

Piracy-Resistant DNN Watermarking by Block-Wise Image Transformation with Secret Key

In this paper, we propose a novel DNN watermarking method that utilizes ...
research
01/12/2021

DeepiSign: Invisible Fragile Watermark to Protect the Integrityand Authenticity of CNN

Convolutional Neural Networks (CNNs) deployed in real-life applications ...
research
03/05/2021

Transfer Learning-Based Model Protection With Secret Key

We propose a novel method for protecting trained models with a secret ke...
research
07/20/2021

Protecting Semantic Segmentation Models by Using Block-wise Image Encryption with Secret Key from Unauthorized Access

Since production-level trained deep neural networks (DNNs) are of a grea...
research
09/29/2022

Access Control with Encrypted Feature Maps for Object Detection Models

In this paper, we propose an access control method with a secret key for...
research
06/27/2021

Image content dependent semi-fragile watermarking with localized tamper detection

Content-independent watermarks and block-wise independency can be consid...

Please sign up or login with your details

Forgot password? Click here to reset