DNNShield: Embedding Identifiers for Deep Neural Network Ownership Verification

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Stang, Jasper, Krauß, Torsten, Dmitrienko, Alexandra
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913260792446976
author Stang, Jasper
Krauß, Torsten
Dmitrienko, Alexandra
author_facet Stang, Jasper
Krauß, Torsten
Dmitrienko, Alexandra
contents The surge in popularity of machine learning (ML) has driven significant investments in training Deep Neural Networks (DNNs). However, these models that require resource-intensive training are vulnerable to theft and unauthorized use. This paper addresses this challenge by introducing DNNShield, a novel approach for DNN protection that integrates seamlessly before training. DNNShield embeds unique identifiers within the model architecture using specialized protection layers. These layers enable secure training and deployment while offering high resilience against various attacks, including fine-tuning, pruning, and adaptive adversarial attacks. Notably, our approach achieves this security with minimal performance and computational overhead (less than 5\% runtime increase). We validate the effectiveness and efficiency of DNNShield through extensive evaluations across three datasets and four model architectures. This practical solution empowers developers to protect their DNNs and intellectual property rights.
format Preprint
id arxiv_https___arxiv_org_abs_2403_06581
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DNNShield: Embedding Identifiers for Deep Neural Network Ownership Verification
Stang, Jasper
Krauß, Torsten
Dmitrienko, Alexandra
Cryptography and Security
The surge in popularity of machine learning (ML) has driven significant investments in training Deep Neural Networks (DNNs). However, these models that require resource-intensive training are vulnerable to theft and unauthorized use. This paper addresses this challenge by introducing DNNShield, a novel approach for DNN protection that integrates seamlessly before training. DNNShield embeds unique identifiers within the model architecture using specialized protection layers. These layers enable secure training and deployment while offering high resilience against various attacks, including fine-tuning, pruning, and adaptive adversarial attacks. Notably, our approach achieves this security with minimal performance and computational overhead (less than 5\% runtime increase). We validate the effectiveness and efficiency of DNNShield through extensive evaluations across three datasets and four model architectures. This practical solution empowers developers to protect their DNNs and intellectual property rights.
title DNNShield: Embedding Identifiers for Deep Neural Network Ownership Verification
topic Cryptography and Security
url https://arxiv.org/abs/2403.06581