Intellectual Property Protection for Deep Learning Models: Taxonomy, Methods, Attacks, and Evaluations
arXiv:2011.13564 · doi:10.1109/TAI.2021.3133824
Abstract
The training and creation of deep learning model is usually costly, thus it can be regarded as an intellectual property (IP) of the model creator. However, malicious users who obtain high-performance models may illegally copy, redistribute, or abuse the models without permission. To deal with such security threats, a few deep neural networks (DNN) IP protection methods have been proposed in recent years. This paper attempts to provide a review of the existing DNN IP protection works and also an outlook. First, we propose the first taxonomy for DNN IP protection methods in terms of six attributes: scenario, mechanism, capacity, type, function, and target models. Then, we present a survey on existing DNN IP protection works in terms of the above six attributes, especially focusing on the challenges these methods face, whether these methods can provide proactive protection, and their resistances to different levels of attacks. After that, we analyze the potential attacks on DNN IP protection methods from the aspects of model modifications, evasion attacks, and active attacks. Besides, a systematic evaluation method for DNN IP protection methods with respect to basic functional metrics, attack-resistance metrics, and customized metrics for different application scenarios is given. Lastly, future research opportunities and challenges on DNN IP protection are presented.
References in corpus (17)
- Explaining and Harnessing Adversarial Examples
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Stealing Machine Learning Models via Prediction APIs
- Reversible Watermarking in Deep Convolutional Neural Networks for Integrity Authentication
- AdvParams: An Active DNN Intellectual Property Protection Technique via Adversarial Perturbation Based Parameter Encryption
- BlackMarks: Blackbox Multibit Watermarking for Deep Neural Networks
- Passport-aware Normalization for Deep Model Protection
- Effectiveness of Distillation Attack and Countermeasure on Neural Network Watermarking
- NaturalAE: Natural and Robust Physical Adversarial Examples for Object Detectors
- Removing Backdoor-Based Watermarks in Neural Networks with Limited Data
- Detect and remove watermark in deep neural networks via generative adversarial networks
- Deep Serial Number: Computational Watermarking for DNN Intellectual Property Protection
- Digital Passport: A Novel Technological Strategy for Intellectual Property Protection of Convolutional Neural Networks
- Training DNN Model with Secret Key for Model Protection
- MimosaNet: An Unrobust Neural Network Preventing Model Stealing
- Deep-Lock: Secure Authorization for Deep Neural Networks
- WAFFLE: Watermarking in Federated Learning
Cited by in corpus (7)
- A Survey on Digital Twins: Architecture, Enabling Technologies, Security and Privacy, and Future Prospects
- AdvParams: An Active DNN Intellectual Property Protection Technique via Adversarial Perturbation Based Parameter Encryption
- Protecting the Intellectual Properties of Deep Neural Networks with an Additional Class and Steganographic Images
- ActiveGuard: An Active DNN IP Protection Technique via Adversarial Examples
- InFIP: An Explainable DNN Intellectual Property Protection Method based on Intrinsic Features
- An Efficient Watermarking Method for Latent Diffusion Models via Low-Rank Adaptation and Dynamic Loss Weighting
- Watermarking Neuromorphic Brains: Intellectual Property Protection in Spiking Neural Networks