Intellectual Property Protection for Deep Learning Models: Taxonomy, Methods, Attacks, and Evaluations

被引:21
|
作者
Xue M. [1 ]
Zhang Y. [1 ]
Wang J. [1 ]
Liu W. [2 ]
机构
[1] Nanjing University of Aeronautics and Astronautics, College of Computer Science and Technology, Nanjing
[2] Nanjing University of Aeronautics and Astronautics, College of Electronic and Information Engineering, Nanjing
来源
基金
中国国家自然科学基金;
关键词
Attack resistance; deep neural network (DNN); intellectual property (IP) protection; machine learning security; taxonomy;
D O I
10.1109/TAI.2021.3133824
中图分类号
学科分类号
摘要
The training and creation of deep learning model is usually costly, thus the trained model can be regarded as an intellectual property (IP) of the model creator. However, malicious users who obtain high-performance models may illegally copy, redistribute, or abuse the models without permission. To deal with such security threats, a few deep neural networks (DNN) IP protection methods have been proposed in recent years. This article attempts to provide a review of the existing DNN IP protection works and also an outlook. First, we propose the first taxonomy for DNN IP protection methods in terms of six attributes - scenario, mechanism, capacity, type, function, and target models. Then, we present a survey on existing DNN IP protection works in terms of the above six attributes, especially focusing on the challenges these methods face, whether these methods can provide proactive protection, and their resistances to different levels of attacks. After that, we analyze the potential attacks on DNN IP protection methods from the aspects of model modifications, evasion attacks, and active attacks. Besides, a systematic evaluation method for DNN IP protection methods with respect to basic functional metrics, attack-resistance metrics, and customized metrics for different application scenarios is given. Finally, challenges and future research opportunities on DNN IP protection are presented. © 2020 IEEE.
引用
收藏
页码:908 / 923
页数:15
相关论文
共 50 条
  • [1] Intellectual Property (IP) Protection for Deep Learning and Federated Learning Models
    Koushanfar, Farinaz
    PROCEEDINGS OF THE 2022 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH-MMSEC 2022, 2022, : 5 - 5
  • [2] Hardware-Assisted Intellectual Property Protection of Deep Learning Models
    Chakraborty, Abhishek
    Mondal, Ankit
    Srivastava, Ankur
    PROCEEDINGS OF THE 2020 57TH ACM/EDAC/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2020,
  • [3] Taxonomy in software intellectual property protection
    Jaffrey, K
    Bonyuet, D
    Youcef-Toumi, K
    CCCT 2003, VOL 1, PROCEEDINGS: COMPUTING/INFORMATION SYSTEMS AND TECHNOLOGIES, 2003, : 141 - 146
  • [4] Intellectual property protection for deep semantic segmentation models
    Hongjia Ruan
    Huihui Song
    Bo Liu
    Yong Cheng
    Qingshan Liu
    Frontiers of Computer Science, 2023, 17
  • [5] Intellectual property protection for deep semantic segmentation models
    Ruan, Hongjia
    Song, Huihui
    Liu, Bo
    Cheng, Yong
    Liu, Qingshan
    FRONTIERS OF COMPUTER SCIENCE, 2023, 17 (01)
  • [6] Identifying Appropriate Intellectual Property Protection Mechanisms for Machine Learning Models: A Systematization of Watermarking, Fingerprinting, Model Access, and Attacks
    Lederer, Isabell
    Mayer, Rudolf
    Rauber, Andreas
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (10) : 13082 - 13100
  • [7] Intellectual property protection of DNN models
    Sen Peng
    Yufei Chen
    Jie Xu
    Zizhuo Chen
    Cong Wang
    Xiaohua Jia
    World Wide Web, 2023, 26 : 1877 - 1911
  • [8] Intellectual property protection of DNN models
    Peng, Sen
    Chen, Yufei
    Xu, Jie
    Chen, Zizhuo
    Wang, Cong
    Jia, Xiaohua
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2023, 26 (04): : 1877 - 1911
  • [9] Intellectual Property Protection of Deep Neural Network Models Based on Watermarking Technology
    Jin, Biao
    Lin, Xiang
    Xiong, Jinbo
    You, Weijing
    Li, Xuan
    Yao, Zhiqiang
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2024, 61 (10): : 2587 - 2606
  • [10] Deep Model Intellectual Property Protection via Deep Watermarking
    Zhang, Jie
    Chen, Dongdong
    Liao, Jing
    Zhang, Weiming
    Feng, Huamin
    Hua, Gang
    Yu, Nenghai
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2022, 44 (08) : 4005 - 4020