DeepMarks: A Digital Fingerprinting Framework for Deep Neural Networks

04/10/2018
by   Huili Chen, et al.
0

This paper proposes DeepMarks, a novel end-to-end framework for systematic fingerprinting in the context of Deep Learning (DL). Remarkable progress has been made in the area of deep learning. Sharing the trained DL models has become a trend that is ubiquitous in various fields ranging from biomedical diagnosis to stock prediction. As the availability and popularity of pre-trained models are increasing, it is critical to protect the Intellectual Property (IP) of the model owner. DeepMarks introduces the first fingerprinting methodology that enables the model owner to embed unique fingerprints within the parameters (weights) of her model and later identify undesired usages of her distributed models. The proposed framework embeds the fingerprints in the Probability Density Function (pdf) of trainable weights by leveraging the extra capacity available in contemporary DL models. DeepMarks is robust against fingerprints collusion as well as network transformation attacks, including model compression and model fine-tuning. Extensive proof-of-concept evaluations on MNIST and CIFAR10 datasets, as well as a wide variety of deep neural networks architectures such as Wide Residual Networks (WRNs) and Convolutional Neural Networks (CNNs), corroborate the effectiveness and robustness of DeepMarks framework.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/02/2018

DeepSigns: A Generic Watermarking Framework for IP Protection of Deep Learning Models

This paper proposes DeepSigns, a novel end-to-end framework for systemat...
research
09/08/2017

CuRTAIL: ChaRacterizing and Thwarting AdversarIal deep Learning

This paper proposes CuRTAIL, an end-to-end computing framework for chara...
research
01/15/2017

Embedding Watermarks into Deep Neural Networks

Deep neural networks have recently achieved significant progress. Sharin...
research
07/14/2023

Multiplicative update rules for accelerating deep learning training and increasing robustness

Even nowadays, where Deep Learning (DL) has achieved state-of-the-art pe...
research
10/16/2018

ReDMark: Framework for Residual Diffusion Watermarking on Deep Networks

Due to the rapid growth of machine learning tools and specifically deep ...
research
10/31/2020

DL-Reg: A Deep Learning Regularization Technique using Linear Regression

Regularization plays a vital role in the context of deep learning by pre...
research
07/27/2022

DynaMarks: Defending Against Deep Learning Model Extraction Using Dynamic Watermarking

The functionality of a deep learning (DL) model can be stolen via model ...

Please sign up or login with your details

Forgot password? Click here to reset