Please use this identifier to cite or link to this item:
https://hdl.handle.net/10356/162779
Full metadata record
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Zheng, Yue | en_US |
dc.contributor.author | Wang, Si | en_US |
dc.contributor.author | Chang, Chip Hong | en_US |
dc.date.accessioned | 2022-11-09T04:57:15Z | - |
dc.date.available | 2022-11-09T04:57:15Z | - |
dc.date.issued | 2022 | - |
dc.identifier.citation | Zheng, Y., Wang, S. & Chang, C. H. (2022). A DNN fingerprint for non-repudiable model ownership identification and piracy detection. IEEE Transactions On Information Forensics and Security, 17, 2977-2989. https://dx.doi.org/10.1109/TIFS.2022.3198267 | en_US |
dc.identifier.issn | 1556-6013 | en_US |
dc.identifier.uri | https://hdl.handle.net/10356/162779 | - |
dc.description.abstract | A high-performance Deep Neural Network (DNN) model is a valuable intellectual property (IP) since designing and training such a model from scratch is very costly. Model transfer learning, compression and retraining are commonly used by pirates to evade detection or even redeploy the pirated models for new applications without compromising performance. This paper presents a novel non-intrusive DNN IP fingerprinting method that can detect pirated models and provide a nonrepudiable and irrevocable ownership proof simultaneously. The fingerprint is derived from projecting a subset of front-layer weights onto a model owner identity defined random space to enable a distinguisher to differentiate pirated models that are used in the same application or retrained for a different task from originally designed DNN models. The proposed method generates compact and irrevocable fingerprints against model IP misappropriation and ownership fraud. It requires no retraining and makes no modification to the original model. The proposed fingerprinting method is evaluated on nine original DNN models trained on CIFAR-10, CIFAR-100, and ImageNet-10. It is demonstrated to have the highest discriminative power among existing fingerprinting methods in detecting pirated models deployed for the same and different applications, and fraudulent model IP ownership claims. | en_US |
dc.description.sponsorship | National Research Foundation (NRF) | en_US |
dc.language.iso | en | en_US |
dc.relation | CHFA-GC1-AW01 | en_US |
dc.relation.ispartof | IEEE Transactions on Information Forensics and Security | en_US |
dc.rights | © 2022 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. The published version is available at: https://doi.org/10.1109/TIFS.2022.3198267. | en_US |
dc.subject | Engineering::Electrical and electronic engineering | en_US |
dc.title | A DNN fingerprint for non-repudiable model ownership identification and piracy detection | en_US |
dc.type | Journal Article | en |
dc.contributor.school | School of Electrical and Electronic Engineering | en_US |
dc.contributor.research | Centre for Integrated Circuits and Systems | en_US |
dc.identifier.doi | 10.1109/TIFS.2022.3198267 | - |
dc.description.version | Submitted/Accepted version | en_US |
dc.identifier.volume | 17 | en_US |
dc.identifier.spage | 2977 | en_US |
dc.identifier.epage | 2989 | en_US |
dc.subject.keywords | DNN IP Protection | en_US |
dc.subject.keywords | Fingerprinting | en_US |
dc.subject.keywords | Random Projection | en_US |
dc.subject.keywords | Cross Application | en_US |
dc.subject.keywords | Ownership | en_US |
dc.description.acknowledgement | This research is supported by the National Research Foundation, Singapore, under its National Cybersecurity R&D Programme/Cyber- Hardware Forensic & Assurance Evaluation R&D Programme (Award: CHFA-GC1-AW01). | en_US |
item.grantfulltext | open | - |
item.fulltext | With Fulltext | - |
Appears in Collections: | EEE Journal Articles |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
dnn_ip.pdf | A DNN Fingerprint for Non-repudiable Model Ownership Identification and Piracy Detection | 2.91 MB | Adobe PDF | ![]() View/Open |
SCOPUSTM
Citations
50
3
Updated on Nov 30, 2023
Web of ScienceTM
Citations
50
2
Updated on Oct 23, 2023
Page view(s)
95
Updated on Dec 3, 2023
Download(s) 50
65
Updated on Dec 3, 2023
Google ScholarTM
Check
Altmetric
Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.