Adversarial Frontier Stitching for Remote Neural Network Watermarking
arXiv:1711.01894 · doi:10.1007/s00521-019-04434-z
Abstract
The state of the art performance of deep learning models comes at a high cost for companies and institutions, due to the tedious data collection and the heavy processing requirements. Recently, [35, 22] proposed to watermark convolutional neural networks for image classification, by embedding information into their weights. While this is a clear progress towards model protection, this technique solely allows for extracting the watermark from a network that one accesses locally and entirely. Instead, we aim at allowing the extraction of the watermark from a neural network (or any other machine learning model) that is operated remotely, and available through a service API. To this end, we propose to mark the model's action itself, tweaking slightly its decision frontiers so that a set of specific queries convey the desired information. In the present paper, we formally introduce the problem and propose a novel zero-bit watermarking algorithm that makes use of adversarial model examples. While limiting the loss of performance of the protected model, this algorithm allows subsequent extraction of the watermark using only few queries. We experimented the approach on three neural networks designed for image classification, in the context of MNIST digit recognition task.
To appear in the journal of Neural Computing and Applications, 2019
References in corpus (10)
- Explaining and Harnessing Adversarial Examples
- Ensemble Adversarial Training: Attacks and Defenses
- A Simple Way to Initialize Recurrent Networks of Rectified Linear Units
- Adversarial Frontier Stitching for Remote Neural Network Watermarking
- Digital Watermarking for Deep Neural Networks
- Stealing Neural Networks via Timing Side Channels
- DeepSigns: A Generic Watermarking Framework for IP Protection of Deep Learning Models
- Adversarial Perturbations Against Real-Time Video Classification Systems
- Data Driven Exploratory Attacks on Black Box Classifiers in Adversarial Domains
- An Empirical Evaluation of Adversarial Robustness under Transfer Learning
Cited by in corpus (55)
- Adversarial Frontier Stitching for Remote Neural Network Watermarking
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring
- A Systematic Review on Model Watermarking for Neural Networks
- Intellectual Property Protection for Deep Learning Models: Taxonomy, Methods, Attacks, and Evaluations
- DAWN: Dynamic Adversarial Watermarking of Neural Networks
- DeepMarks: A Digital Fingerprinting Framework for Deep Neural Networks
- AdvParams: An Active DNN Intellectual Property Protection Technique via Adversarial Perturbation Based Parameter Encryption
- BlackMarks: Blackbox Multibit Watermarking for Deep Neural Networks
- Watermarking Graph Neural Networks by Random Graphs
- Have You Stolen My Model? Evasion Attacks Against Deep Neural Network Watermarking Techniques
- Identifying Appropriate Intellectual Property Protection Mechanisms for Machine Learning Models: A Systematization of Watermarking, Fingerprinting, Model Access, and Attacks
- Passport-aware Normalization for Deep Model Protection
- Deep Fidelity in DNN Watermarking: A Study of Backdoor Watermarking for Classification Models
- Protecting the Intellectual Properties of Deep Neural Networks with an Additional Class and Steganographic Images
- Effectiveness of Distillation Attack and Countermeasure on Neural Network Watermarking
- Deep Neural Network Fingerprinting by Conferrable Adversarial Examples
- Model extraction from counterfactual explanations
- IPGuard: Protecting Intellectual Property of Deep Neural Networks via Fingerprinting the Classification Boundary
- Image and Model Transformation with Secret Key for Vision Transformer
- Removing Backdoor-Based Watermarks in Neural Networks with Limited Data
- Performance Comparison of Contemporary DNN Watermarking Techniques
- Robust Watermarking of Neural Network with Exponential Weighting
- RIGA: Covert and Robust White-Box Watermarking of Deep Neural Networks
- Generating Image Adversarial Examples by Embedding Digital Watermarks
- Detect and remove watermark in deep neural networks via generative adversarial networks
- Speech Pattern based Black-box Model Watermarking for Automatic Speech Recognition
- Evolutionary Trigger Set Generation for DNN Black-Box Watermarking
- Secure Watermark for Deep Neural Networks with Multi-task Learning
- Towards Practical Watermark for Deep Neural Networks in Federated Learning
- You are caught stealing my winning lottery ticket! Making a lottery ticket claim its ownership
- Decentralized Attribution of Generative Models
- Neural Dehydration: Effective Erasure of Black-box Watermarks from DNNs with Limited Data
- InFIP: An Explainable DNN Intellectual Property Protection Method based on Intrinsic Features
- SoK: How Robust is Image Classification Deep Neural Network Watermarking? (Extended Version)
- Training DNN Model with Secret Key for Model Protection
- Digital Passport: A Novel Technological Strategy for Intellectual Property Protection of Convolutional Neural Networks
- Protect, Show, Attend and Tell: Empowering Image Captioning Models with Ownership Protection
- Access Control Using Spatially Invariant Permutation of Feature Maps for Semantic Segmentation Models
- ChainMarks: Securing DNN Watermark with Cryptographic Chain
- Spread-Transform Dither Modulation Watermarking of Deep Neural Network
- HufuNet: Embedding the Left Piece as Watermark and Keeping the Right Piece for Ownership Verification in Deep Neural Networks
- WAFFLE: Watermarking in Federated Learning
- [Extended version] Rethinking Deep Neural Network Ownership Verification: Embedding Passports to Defeat Ambiguity Attacks
- A survey of deep neural network watermarking techniques
- Protecting Intellectual Property of Generative Adversarial Networks from Ambiguity Attack
- Hot-Swap MarkBoard: An Efficient Black-box Watermarking Approach for Large-scale Model Distribution
- A Protection Method of Trained CNN Model Using Feature Maps Transformed With Secret Key From Unauthorized Access
- Model Watermarking for Image Processing Networks
- Access Control with Encrypted Feature Maps for Object Detection Models
- Watermarking Neuromorphic Brains: Intellectual Property Protection in Spiking Neural Networks
- Watermarking Recommender Systems
- FBI: Fingerprinting models with Benign Inputs
- iNNformant: Boundary Samples as Telltale Watermarks
- High-Robustness, Low-Transferability Fingerprinting of Neural Networks
- S4oC: A Self-optimizing, Self-adapting Secure System-on-Chip Design Framework to Tackle Unknown Threats -- A Network Theoretic, Learning Approach