论文标题

深序列号:DNN知识产权保护的计算水印

Deep Serial Number: Computational Watermarking for DNN Intellectual Property Protection

论文作者

Tang, Ruixiang, Du, Mengnan, Hu, Xia

论文摘要

在本文中,我们提出了DSN(深序列号),这是一种专门为深神经网络(DNNS)设计的简单而有效的水印算法。与将识别信号纳入DNN的传统方法不同,我们的方法探讨了DNN的新型知识产权(IP)保护机制,有效地阻止了对手使用被盗网络。受到序列号成功在保护常规软件IP中的成功的启发,我们提出了第一个在DNN中嵌入序列号的实现。为了实现这一目标,DSN被整合到知识蒸馏框架中,其中最初对私人教师DNN进行了培训。随后,它的知识被蒸馏而来,并授予一系列定制的学生DNN。每个客户DNN仅在输入有效的序列号后才能正确运行。各种应用程序的实验结果表明,DSN在不损害原始DNN性能的情况下防止未经授权使用的功效。该实验进一步表明,DSN对不同类别的水印攻击具有抵抗力。

In this paper, we present DSN (Deep Serial Number), a simple yet effective watermarking algorithm designed specifically for deep neural networks (DNNs). Unlike traditional methods that incorporate identification signals into DNNs, our approach explores a novel Intellectual Property (IP) protection mechanism for DNNs, effectively thwarting adversaries from using stolen networks. Inspired by the success of serial numbers in safeguarding conventional software IP, we propose the first implementation of serial number embedding within DNNs. To achieve this, DSN is integrated into a knowledge distillation framework, in which a private teacher DNN is initially trained. Subsequently, its knowledge is distilled and imparted to a series of customized student DNNs. Each customer DNN functions correctly only upon input of a valid serial number. Experimental results across various applications demonstrate DSN's efficacy in preventing unauthorized usage without compromising the original DNN performance. The experiments further show that DSN is resistant to different categories of watermark attacks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源