Identifying Appropriate Intellectual Property Protection Mechanisms for Machine Learning Models: A Systematization of Watermarking, Fingerprinting, Model Access, and Attacks
arXiv:2304.11285 · doi:10.1109/TNNLS.2023.3270135
Abstract
The commercial use of Machine Learning (ML) is spreading; at the same time, ML models are becoming more complex and more expensive to train, which makes Intellectual Property Protection (IPP) of trained models a pressing issue. Unlike other domains that can build on a solid understanding of the threats, attacks and defenses available to protect their IP, the ML-related research in this regard is still very fragmented. This is also due to a missing unified view as well as a common taxonomy of these aspects. In this paper, we systematize our findings on IPP in ML, while focusing on threats and attacks identified and defenses proposed at the time of writing. We develop a comprehensive threat model for IP in ML, categorizing attacks and defenses within a unified and consolidated taxonomy, thus bridging research from both the ML and security communities.
References in corpus (7)
- Reversible Watermarking in Deep Convolutional Neural Networks for Integrity Authentication
- BlackMarks: Blackbox Multibit Watermarking for Deep Neural Networks
- Effectiveness of Distillation Attack and Countermeasure on Neural Network Watermarking
- Sequential Triggers for Watermarking of Deep Reinforcement Learning Policies
- A Comprehensive Survey of Watermarking Relational Databases Research
- Stealing Knowledge from Protected Deep Neural Networks Using Composite Unlabeled Data
- A novel method for identifying the deep neural network model with the Serial Number