###
计算机系统应用英文版:2024,33(4):1-12
本文二维码信息
码上扫一扫!
基于显著图的高隐蔽性模型指纹算法
(复旦大学 计算机科学技术学院, 上海 200438)
High-stealthiness Model Fingerprint Algorithm Based on Saliency Map
(School of Computer Science, Fudan University, Shanghai 200438, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 563次   下载 1288
Received:October 11, 2023    Revised:November 09, 2023
中文摘要: 在核心任务场景下训练深度神经网络 (DNN) 需要越来越多的算力资源, 这刺激了基于云端预测API接口的模型的窃取与盗用, 同时也违反了模型所有者的知识产权. 为了追踪公开的非法模型副本, 深度神经网络的模型指纹技术为希望保持模型完整性的模型所有者提供了一种强大的版权验证方案. 然而, 现有的模型指纹方案主要基于输出层面的内在痕迹 (例如: 特定输入样本下的错误预测行为) , 这导致在模型指纹验证阶段缺乏隐蔽性. 本文基于模型预测时的显著图 (saliency map) 痕迹, 提出了一种全新的任意下游任务通用的模型指纹方案. 本文的方案提出了受约束的显著图操控目标, 构建标签不变和自然的指纹样本, 显著提高了模型指纹的隐蔽性. 根据对3种典型任务场景下全面的评估结果, 本文提出的方法被证明能够显著地增强现有方案的指纹版权验证的效果, 同时保持高度的模型指纹隐蔽性.
Abstract:Training of deep neural networks (DNN) in mission-critical scenarios involves increasingly more resources, which stimulates model stealing from prediction API at the cloud and violates the intellectual property rights of the model owners. To trace public illegal model copies, DNN model fingerprint provides a promising copyright verification option for model owners who want to preserve the model integrity. However, existing fingerprinting schemes are mainly based on output-level traces (e.g., mis-prediction behavior on special inputs) to cause limited stealthiness during model fingerprint verification. This study proposes a novel task-agnostic fingerprinting scheme based on saliency map traces of model prediction. The proposed scheme puts forward a constrained manipulation objective of saliency maps to construct clean-label and natural fingerprint samples, thus significantly improving the stealthiness of model fingerprints. According to extensive evaluation results on three typical tasks, this scheme is proven to substantially enhance the fingerprint effectiveness of existing schemes and remain highly stealthy of model fingerprints.
文章编号:     中图分类号:    文献标志码:
基金项目:国家自然科学基金(61972099)
引用文本:
张圣尧,潘旭东,张谧.基于显著图的高隐蔽性模型指纹算法.计算机系统应用,2024,33(4):1-12
ZHANG Sheng-Yao,PAN Xu-Dong,ZHANG Mi.High-stealthiness Model Fingerprint Algorithm Based on Saliency Map.COMPUTER SYSTEMS APPLICATIONS,2024,33(4):1-12