Please use this identifier to cite or link to this item: https://hdl.handle.net/10356/176640
Title: Defending against model extraction attacks via watermark-based method with knowledge distillation
Authors: Zhang, Siting
Keywords: Engineering
Issue Date: 2024
Publisher: Nanyang Technological University
Source: Zhang, S. (2024). Defending against model extraction attacks via watermark-based method with knowledge distillation. Final Year Project (FYP), Nanyang Technological University, Singapore. https://hdl.handle.net/10356/176640
Project: A2044-231 
Abstract: Developing deep neural network (DNN) models often requires significant investment in computational resources, expertise, and vast amount of data. The increasing popularity of Machine Learning as a Service (MLaaS) offers convenient access to these powerful models, but it also raises concerns about Intellectual Property (IP) protection. Model extraction attacks pose a significant threat, allowing unauthorized parties to steal a model's functionality and potentially exploit it for their own gain. Traditional passive watermarking methods often prove inadequate against determined adversaries. This project presents a novel Intellectual Property Protection (IPP) method for deep neural network (DNN) models. The approach leverages watermarking techniques, a Mixture-of-Experts (MoE) architecture, and knowledge distillation to enhance model security while preserving its core functionality. Authorized users can unlock the full potential of the model by embedding a specific watermark into their input images. Crucially, this solution facilitates robust ownership verification, even in black-box scenarios where model extraction attempts occur. Experimental results demonstrate the effective implementation of this method with minimal impact on the model's primary task. This work contributes to strengthening IP protection within Machine Learning as a Service (MLaaS) environments.
URI: https://hdl.handle.net/10356/176640
Schools: School of Electrical and Electronic Engineering 
Fulltext Permission: restricted
Fulltext Availability: With Fulltext
Appears in Collections:EEE Student Reports (FYP/IA/PA/PI)

Files in This Item:
File Description SizeFormat 
FYP_Final_Report.pdf
  Restricted Access
2.36 MBAdobe PDFView/Open

Page view(s)

91
Updated on May 5, 2025

Download(s)

3
Updated on May 5, 2025

Google ScholarTM

Check

Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.