Authority Backdoor: A Certifiable Backdoor Mechanism for Authoring DNNs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Han, Li, Shaofeng, Dong, Tian, Xu, Xiangyu, Liu, Guangchi, Ling, Zhen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917138727436288
author Yang, Han
Li, Shaofeng
Dong, Tian
Xu, Xiangyu
Liu, Guangchi
Ling, Zhen
author_facet Yang, Han
Li, Shaofeng
Dong, Tian
Xu, Xiangyu
Liu, Guangchi
Ling, Zhen
contents Deep Neural Networks (DNNs), as valuable intellectual property, face unauthorized use. Existing protections, such as digital watermarking, are largely passive; they provide only post-hoc ownership verification and cannot actively prevent the illicit use of a stolen model. This work proposes a proactive protection scheme, dubbed ``Authority Backdoor," which embeds access constraints directly into the model. In particular, the scheme utilizes a backdoor learning framework to intrinsically lock a model's utility, such that it performs normally only in the presence of a specific trigger (e.g., a hardware fingerprint). But in its absence, the DNN's performance degrades to be useless. To further enhance the security of the proposed authority scheme, the certifiable robustness is integrated to prevent an adaptive attacker from removing the implanted backdoor. The resulting framework establishes a secure authority mechanism for DNNs, combining access control with certifiable robustness against adversarial attacks. Extensive experiments on diverse architectures and datasets validate the effectiveness and certifiable robustness of the proposed framework.
format Preprint
id arxiv_https___arxiv_org_abs_2512_10600
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Authority Backdoor: A Certifiable Backdoor Mechanism for Authoring DNNs
Yang, Han
Li, Shaofeng
Dong, Tian
Xu, Xiangyu
Liu, Guangchi
Ling, Zhen
Cryptography and Security
Machine Learning
Deep Neural Networks (DNNs), as valuable intellectual property, face unauthorized use. Existing protections, such as digital watermarking, are largely passive; they provide only post-hoc ownership verification and cannot actively prevent the illicit use of a stolen model. This work proposes a proactive protection scheme, dubbed ``Authority Backdoor," which embeds access constraints directly into the model. In particular, the scheme utilizes a backdoor learning framework to intrinsically lock a model's utility, such that it performs normally only in the presence of a specific trigger (e.g., a hardware fingerprint). But in its absence, the DNN's performance degrades to be useless. To further enhance the security of the proposed authority scheme, the certifiable robustness is integrated to prevent an adaptive attacker from removing the implanted backdoor. The resulting framework establishes a secure authority mechanism for DNNs, combining access control with certifiable robustness against adversarial attacks. Extensive experiments on diverse architectures and datasets validate the effectiveness and certifiable robustness of the proposed framework.
title Authority Backdoor: A Certifiable Backdoor Mechanism for Authoring DNNs
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2512.10600