paper-with-me

홈 › Papers

ActiveGuard: An Active DNN IP Protection Technique via Adversarial Examples

2021-03-02 · Mingfu Xue, Shichang Sun, Can He, Yushu Zhang, Jian Wang, Weiqiang Liu

The training of Deep Neural Networks (DNN) is costly, thus DNN can be considered as the intellectual properties (IP) of model owners. To date, most of the existing protection works focus on verifying the ownership after the DNN model is stolen, which cannot resist piracy in advance. To this end, we propose an active DNN IP protection method based on adversarial examples against DNN piracy, named ActiveGuard. ActiveGuard aims to achieve authorization control and users' fingerprints management through adversarial examples, and can provide ownership verification. Specifically, ActiveGuard exploits the elaborate adversarial examples as users' fingerprints to distinguish authorized users from unauthorized users. Legitimate users can enter fingerprints into DNN for identity authentication and authorized usage, while unauthorized users will obtain poor model performance due to an additional control layer. In addition, ActiveGuard enables the model owner to embed a watermark into the weights of DNN. When the DNN is illegally pirated, the model owner can extract the embedded watermark and perform ownership verification. Experimental results show that, for authorized users, the test accuracy of LeNet-5 and Wide Residual Network (WRN) models are 99.15% and 91.46%, respectively, while for unauthorized users, the test accuracy of the two DNNs are only 8.92% (LeNet-5) and 10% (WRN), respectively. Besides, each authorized user can pass the fingerprint authentication with a high success rate (up to 100%). For ownership verification, the embedded watermark can be successfully extracted, while the normal performance of the DNN model will not be affected. Further, ActiveGuard is demonstrated to be robust against fingerprint forgery attack, model fine-tuning attack and pruning attack.

📄 PDF Abstract BibTeX arXiv:2103.01527

Code (0)

등록된 구현이 없습니다.

Tasks

Management

Methods 이 논문이 사용한 방법론

Pruning 설명 없음

Similar Papers 제목 키워드 기반

Self-recoverable Adversarial Examples: A New Effective Protection Mechanism in Social Networks

2022-04-26 · Jiawei Zhang, Jinwei Wang, Hao Wang, Xiangyang Luo

Malicious intelligent algorithms greatly threaten the security of social users' privacy by detecting and analyzing the uploaded photos to social network platforms. The destruction to DNNs brought by the adversarial attac…

Adversarial AttackAdversarial DefenseGenerative Adversarial Network

I2VShield: An Efficient Proactive Defense Framework against DiT-based Image-to-Video Models

2026-07-28 · Yimao Guo, Zuomin Qu, Wei Lu arxiv

The rapid advancement of video generation models has led to the increasing misuse of image-to-video (I2V) models. Although substantial progress has been made in detecting AI-generated videos, proactive defenses against I…

Video Generation

Rethinking Adversarial Examples for Location Privacy Protection

2022-06-28 · Trung-Nghia Le, Ta Gu, Huy H. Nguyen, Isao Echizen

We have investigated a new application of adversarial examples, namely location privacy protection against landmark recognition systems. We introduce mask-guided multimodal projected gradient descent (MM-PGD), in which a…

Image ManipulationLandmark Recognition

Learning with Protection: Rejection of Suspicious Samples under Adversarial Environment

2019-09-25 · Masahiro Kato, Yoshihiro Fukuhara, Hirokatsu Kataoka, Shigeo Morishima

We propose a novel framework for avoiding the misclassification of data by using a framework of learning with rejection and adversarial examples. Recent developments in machine learning have opened new opportunities for …

BIG-bench Machine LearningBinary ClassificationDecision MakingMulti-class Classification+1

Adversarial Speech Generation and Natural Speech Recovery for Speech Content Protection

2022-06-01 · LREC 2022 6 · Sheng Li, Jiyi Li, Qianying Liu, Zhuo Gong

With the advent of the General Data Protection Regulation (GDPR) and increasing privacy concerns, the sharing of speech data is faced with significant challenges. Protecting the sensitive content of speech is the same im…

speech-recognitionSpeech Recognition