Say No to Freeloader: Protecting Intellectual Property of Your Deep Model

被引:0
|
作者
Wang, Lianyu [1 ]
Wang, Meng [2 ]
Fu, Huazhu [2 ]
Zhang, Daoqiang [1 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Artificial Intelligence, Key Lab Brain Machine Intelligence Technol, Minist Educ, Nanjing 211106, Peoples R China
[2] ASTAR, Agcy Sci Res & Technol, Inst High Performance Comp IHPC, Singapore 138632, Singapore
基金
中国国家自然科学基金;
关键词
Deep learning; deep model IP; domain transfer; WATERMARKING;
D O I
10.1109/TPAMI.2024.3450282
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Model intellectual property (IP) protection has gained attention due to the significance of safeguarding intellectual labor and computational resources. Ensuring IP safety for trainers and owners is critical, especially when ownership verification and applicability authorization are required. A notable approach involves preventing the transfer of well-trained models from authorized to unauthorized domains. We introduce a novel Compact Un-transferable Pyramid Isolation Domain (CUPI-Domain) which serves as a barrier against illegal transfers from authorized to unauthorized domains. Inspired by human transitive inference, the CUPI-Domain emphasizes distinctive style features of the authorized domain, leading to failure in recognizing irrelevant private style features on unauthorized domains. To this end, we propose CUPI-Domain generators, which select features from both authorized and CUPI-Domain as anchors. These generators fuse the style features and semantic features to create labeled, style-rich CUPI-Domain. Additionally, we design external Domain-Information Memory Banks (DIMB) for storing and updating labeled pyramid features to obtain stable domain class features and domain class-wise style features. Based on the proposed whole method, the novel style and discriminative loss functions are designed to effectively enhance the distinction in style and discriminative features between authorized and unauthorized domains. We offer two solutions for utilizing CUPI-Domain based on whether the unauthorized domain is known: target-specified CUPI-Domain and target-free CUPI-Domain. Comprehensive experiments on various public datasets demonstrate the effectiveness of our CUPI-Domain approach with different backbone models, providing an efficient solution for model intellectual property protection.
引用
收藏
页码:11073 / 11086
页数:14
相关论文
共 17 条
  • [1] Protecting Intellectual Property of Deep Neural Networks with Watermarking
    Zhang, Jialong
    Gu, Zhongshu
    Jang, Jiyong
    Wu, Hui
    Stoecklin, Marc Ph
    Huang, Heqing
    Molloy, Ian
    PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, : 159 - 171
  • [2] Your Model Trains on My Data? Protecting Intellectual Property of Training Data via Membership Fingerprint Authentication
    Liu, Gaoyang
    Xu, Tianlong
    Ma, Xiaoqiang
    Wang, Chen
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1024 - 1037
  • [3] Protecting the Intellectual Property of Deep Neural Networks with Watermarking: The Frequency Domain Approach
    Li, Meng
    Zhong, Qi
    Zhang, Leo Yu
    Du, Yajuan
    Zhang, Jun
    Xiang, Yong
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 402 - 409
  • [4] Deep Model Intellectual Property Protection via Deep Watermarking
    Zhang, Jie
    Chen, Dongdong
    Liao, Jing
    Zhang, Weiming
    Feng, Huamin
    Hua, Gang
    Yu, Nenghai
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2022, 44 (08) : 4005 - 4020
  • [5] Protecting Intellectual Property With Reliable Availability of Learning Models in AI-Based Cybersecurity Services
    Ren, Ge
    Wu, Jun
    Li, Gaolei
    Li, Shenghong
    Guizani, Mohsen
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (02) : 600 - 617
  • [6] Intellectual Property (IP) Protection for Deep Learning and Federated Learning Models
    Koushanfar, Farinaz
    PROCEEDINGS OF THE 2022 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH-MMSEC 2022, 2022, : 5 - 5
  • [7] Chaotic Weights: A Novel Approach to Protect Intellectual Property of Deep Neural Networks
    Lin, Ning
    Chen, Xiaoming
    Lu, Hang
    Li, Xiaowei
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2021, 40 (07) : 1327 - 1339
  • [8] Watermarking of Deep Recurrent Neural Network Using Adversarial Examples to Protect Intellectual Property
    Rathi, Pulkit
    Bhadauria, Saumya
    Rathi, Sugandha
    APPLIED ARTIFICIAL INTELLIGENCE, 2022, 36 (01)
  • [9] The state-of-the-art on Intellectual Property Analytics (IPA): A literature review on artificial intelligence, machine learning and deep learning methods for analysing intellectual property (IP) data
    Aristodemou, Leonidas
    Tietze, Frank
    WORLD PATENT INFORMATION, 2018, 55 : 37 - 51
  • [10] LicenseNet: Proactively safeguarding intellectual property of AI models through model license
    Li, Peihao
    Huang, Jie
    Zhang, Shuaishuai
    JOURNAL OF SYSTEMS ARCHITECTURE, 2025, 159