Access Control with Encrypted Feature Maps for Object Detection Models
arXiv:2209.14831 · doi:10.1587/transinf.2022MUP0002
Abstract
In this paper, we propose an access control method with a secret key for object detection models for the first time so that unauthorized users without a secret key cannot benefit from the performance of trained models. The method enables us not only to provide a high detection performance to authorized users but to also degrade the performance for unauthorized users. The use of transformed images was proposed for the access control of image classification models, but these images cannot be used for object detection models due to performance degradation. Accordingly, in this paper, selected feature maps are encrypted with a secret key for training and testing models, instead of input images. In an experiment, the protected models allowed authorized users to obtain almost the same performance as that of non-protected models but also with robustness against unauthorized access without a key.
arXiv admin note: substantial text overlap with arXiv:2206.05422
References in corpus (7)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- PyTorch: An Imperative Style, High-Performance Deep Learning Library
- Explaining and Harnessing Adversarial Examples
- Adversarial Frontier Stitching for Remote Neural Network Watermarking
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring
- Block-wise Scrambled Image Recognition Using Adaptation Network
- Piracy-Resistant DNN Watermarking by Block-Wise Image Transformation with Secret Key