• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Cheng, Hang (Cheng, Hang.) [1] (Scholars:程航) | Li, Xibin (Li, Xibin.) [2] | Wang, Huaxiong (Wang, Huaxiong.) [3] | Zhang, Xinpeng (Zhang, Xinpeng.) [4] | Liu, Ximeng (Liu, Ximeng.) [5] (Scholars:刘西蒙) | Wang, Meiqing (Wang, Meiqing.) [6] (Scholars:王美清) | Li, Fengyong (Li, Fengyong.) [7]

Indexed by:

EI Scopus SCIE

Abstract:

Due to enormous computing and storage overhead for well-trained Deep Neural Network (DNN) models, protecting the intellectual property of model owners is a pressing need. As the commercialization of deep models is becoming increasingly popular, the pre-trained models delivered to users may suffer from being illegally copied, redistributed, or abused. In this paper, we propose DeepDIST, the first end-to-end secure DNNs distribution framework in a black-box scenario. Specifically, our framework adopts a dual-level fingerprint (FP) mechanism to provide reliable ownership verification, and proposes two equivalent transformations that can resist collusion attacks, plus a newly designed similarity loss term to improve the security of the transformations. Unlike the existing passive defense schemes that detect colluding participants, we introduce an active defense strategy, namely damaging the performance of the model after the malicious collusion. The extensive experimental results show that DeepDIST can maintain the accuracy of the host DNN after embedding fingerprint conducted for true traitor tracing, and is robust against several popular model modifications. Furthermore, the anti-collusion effect is evaluated on two typical classification tasks (10-class and 100-class), and the proposed DeepDIST can drop the prediction accuracy of the collusion model to 10% and 1% (random guess), respectively.

Keyword:

anti-collusion Deep neural networks digital fingerprinting digital watermarking

Community:

  • [ 1 ] [Cheng, Hang]Fuzhou Univ, Sch Math & Stat, Fuzhou 350108, Fujian, Peoples R China
  • [ 2 ] [Wang, Meiqing]Fuzhou Univ, Sch Math & Stat, Fuzhou 350108, Fujian, Peoples R China
  • [ 3 ] [Li, Xibin]Fuzhou Univ, Coll Comp Sci & Big Data, Fuzhou 350108, Fujian, Peoples R China
  • [ 4 ] [Liu, Ximeng]Fuzhou Univ, Coll Comp Sci & Big Data, Fuzhou 350108, Fujian, Peoples R China
  • [ 5 ] [Wang, Huaxiong]Nanyang Technol Univ, Sch Phys & Math Sci, Singapore 639798, Singapore
  • [ 6 ] [Zhang, Xinpeng]Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China
  • [ 7 ] [Li, Fengyong]Shanghai Univ Elect Power, Coll Comp Sci & Technol, Shanghai 201306, Peoples R China

Reprint 's Address:

  • [Liu, Ximeng]Fuzhou Univ, Coll Comp Sci & Big Data, Fuzhou 350108, Fujian, Peoples R China;;

Show more details

Version:

Related Keywords:

Related Article:

Source :

IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY

ISSN: 1051-8215

Year: 2024

Issue: 1

Volume: 34

Page: 97-109

8 . 3 0 0

JCR@2023

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count: 1

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 0

Online/Total:31/10033199
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1