paper-with-me

홈 › Papers

Passport-aware Normalization for Deep Model Protection

2020-10-29 · NeurIPS 2020 12 · Jie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang, Gang Hua, Nenghai Yu

Despite tremendous success in many application scenarios, deep learning faces serious intellectual property (IP) infringement threats. Considering the cost of designing and training a good model, infringements will significantly infringe the interests of the original model owner. Recently, many impressive works have emerged for deep model IP protection. However, they either are vulnerable to ambiguity attacks, or require changes in the target network structure by replacing its original normalization layers and hence cause significant performance drops. To this end, we propose a new passport-aware normalization formulation, which is generally applicable to most existing normalization layers and only needs to add another passport-aware branch for IP protection. This new branch is jointly trained with the target model but discarded in the inference stage. Therefore it causes no structure change in the target model. Only when the model IP is suspected to be stolen by someone, the private passport-aware branch is added back for ownership verification. Through extensive experiments, we verify its effectiveness in both image and 3D point recognition models. It is demonstrated to be robust not only to common attack techniques like fine-tuning and model compression, but also to ambiguity attacks. By further combining it with trigger-set based methods, both black-box and white-box verification can be achieved for enhanced security of deep learning models deployed in real systems. Code can be found at https://github.com/ZJZAC/Passport-aware-Normalization.

📄 PDF Abstract BibTeX arXiv:2010.15824

Code (1)

ZJZAC/Passport-aware-Normalization 공식 구현 pytorch

Tasks

modelModel Compression

Similar Papers 제목 키워드 기반

CHIP: Chameleon Hash-based Irreversible Passport for Robust Deep Model Ownership Verification and Active Usage Control

2025-05-30 · Chaohui Xu, Qi Cui, Chip-Hong Chang

The pervasion of large-scale Deep Neural Networks (DNNs) and their enormous training costs make their intellectual property (IP) protection of paramount importance. Recently introduced passport-based methods attempt to s…

Digital Passport: A Novel Technological Strategy for Intellectual Property Protection of Convolutional Neural Networks

2019-05-10 · Lixin Fan, KamWoh Ng, Chee Seng Chan

In order to prevent deep neural networks from being infringed by unauthorized parties, we propose a generic solution which embeds a designated digital passport into a network, and subsequently, either paralyzes the netwo…

General Classificationvalid

Steganographic Passport: An Owner and User Verifiable Credential for Deep Model IP Protection Without Retraining

2024-04-03 · CVPR 2024 1 · Qi Cui, Ruohan Meng, Chaohui Xu, Chip-Hong Chang

Ensuring the legal usage of deep models is crucial to promoting trustable, accountable, and responsible artificial intelligence innovation. Current passport-based methods that obfuscate model functionality for license-to…

Encryption and encoding of facial images into quick response and high capacity color 2d code for biometric passport security system

2022-03-17 · Ziaul Haque Choudhury

In this thesis, a multimodal biometric, secure encrypted data and encrypted biometric encoded into the QR code-based biometric-passport authentication method is proposed for national security applications. Firstly, using…

Inclusive normalization of face images to passport format

2023-12-22 · Hongliu Cao, Minh Nhat Do, Alexis Ravanel, Eoin Thomas

Face recognition has been used more and more in real world applications in recent years. However, when the skin color bias is coupled with intra-personal variations like harsh illumination, the face recognition task is m…

Face IdentificationFace RecognitionFace VerificationFairness