NNSplitter: An Active Defense Solution to DNN Model via Automated Weight Obfuscation

04/28/2023
by   Tong Zhou, et al.
0

As a type of valuable intellectual property (IP), deep neural network (DNN) models have been protected by techniques like watermarking. However, such passive model protection cannot fully prevent model abuse. In this work, we propose an active model IP protection scheme, namely NNSplitter, which actively protects the model by splitting it into two parts: the obfuscated model that performs poorly due to weight obfuscation, and the model secrets consisting of the indexes and original values of the obfuscated weights, which can only be accessed by authorized users. NNSplitter uses the trusted execution environment to secure the secrets and a reinforcement learning-based controller to reduce the number of obfuscated weights while maximizing accuracy drop. Our experiments show that by only modifying 313 out of over 28 million (i.e., 0.001 can drop to 10 against potential attack surfaces, including norm clipping and fine-tuning attacks.

READ FULL TEXT
research
03/21/2023

Effective Ambiguity Attack Against Passport-based DNN Intellectual Property Protection Schemes through Fully Connected Layer Substitution

Since training a deep neural network (DNN) is costly, the well-trained d...
research
11/27/2020

DNN Intellectual Property Protection: Taxonomy, Methods, Attack Resistance, and Evaluations

The training and creation of deep learning model is usually costly, thus...
research
08/13/2020

Deep-Lock: Secure Authorization for Deep Neural Networks

Trained Deep Neural Network (DNN) models are considered valuable Intelle...
research
03/02/2021

ActiveGuard: An Active DNN IP Protection Technique via Adversarial Examples

The training of Deep Neural Networks (DNN) is costly, thus DNN can be co...
research
05/28/2021

AdvParams: An Active DNN Intellectual Property Protection Technique via Adversarial Perturbation Based Parameter Encryption

A well-trained DNN model can be regarded as an intellectual property (IP...
research
06/11/2019

Evolutionary Trigger Set Generation for DNN Black-Box Watermarking

The commercialization of deep learning creates a compelling need for int...
research
08/05/2021

Exploring Structure Consistency for Deep Model Watermarking

The intellectual property (IP) of Deep neural networks (DNNs) can be eas...

Please sign up or login with your details

Forgot password? Click here to reset