SpecMark: A Spectral Watermarking Framework for IP Protection of Speech Recognition Systems

被引:17
作者
Chen, Huili [1 ]
Darvish, Bita [2 ]
Koushanfar, Farinaz [1 ]
机构
[1] Univ Calif San Diego, La Jolla, CA 92093 USA
[2] Microsoft Res, Redmond, WA USA
来源
INTERSPEECH 2020 | 2020年
关键词
speech recognition; intellectual property protection; spectral watermarking;
D O I
10.21437/Interspeech.2020-2787
中图分类号
R36 [病理学]; R76 [耳鼻咽喉科学];
学科分类号
100104 ; 100213 ;
摘要
Automatic Speech Recognition (ASR) systems are widely deployed in various applications due to their superior performance. However, obtaining a highly accurate ASR model is non-trivial since it requires the availability of a massive amount of proprietary training data and enormous computational resources. As such, pre-trained ASR models shall be considered as the intellectual property (IP) of the model designer and protected against copyright infringement attacks. In this paper, we propose SpecMark, the first spectral watermarking framework that seamlessly embeds a watermark (WM) in the spectrum of the ASR model for ownership proof. SpecMark identifies the significant frequency components of the model parameters and encodes the owner's WM in the corresponding spectrum region before sharing the model with end-users. The model builder can later extract the spectral WM to verify his ownership of the marked ASR system. We evaluate SpecMark's performance using DeepSpeech model with three different speech datasets. Empirical results corroborate that SpecMark incurs negligible overhead and preserves the recognition accuracy of the original system. Furthermore, SpecMark sustains diverse model modifications, including parameter pruning and transfer learning.
引用
收藏
页码:2312 / 2316
页数:5
相关论文
共 29 条
[1]  
Adi Y, 2018, PROCEEDINGS OF THE 27TH USENIX SECURITY SYMPOSIUM, P1615
[2]  
Amodei D, 2016, PR MACH LEARN RES, V48
[3]  
Chen H., 2019, ARXIV190400344
[4]  
Chen H., 2018, ARXIV180403648
[5]   DeepAttest: An End-to-End Attestation Framework for Deep Neural Networks [J].
Chen, Huili ;
Fu, Cheng ;
Rouhani, Bita Darvish ;
Zhao, Jishen ;
Koushanfar, Farinaz .
PROCEEDINGS OF THE 2019 46TH INTERNATIONAL SYMPOSIUM ON COMPUTER ARCHITECTURE (ISCA '19), 2019, :487-498
[6]  
Chen X., 2019, ARXIV191107205
[7]   Thyroid Nodule Classification in Ultrasound Images by Fine-Tuning Deep Convolutional Neural Network [J].
Chi, Jianning ;
Walia, Ekta ;
Babyn, Paul ;
Wang, Jimmy ;
Groot, Gary ;
Eramian, Mark .
JOURNAL OF DIGITAL IMAGING, 2017, 30 (04) :477-486
[8]   A Survey on Deep Transfer Learning [J].
Tan, Chuanqi ;
Sun, Fuchun ;
Kong, Tao ;
Zhang, Wenchang ;
Yang, Chao ;
Liu, Chunfang .
ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2018, PT III, 2018, 11141 :270-279
[9]  
Ciresan DC., 2012, C PRESENTATION 2012, P1, DOI [DOI 10.1109/IJCNN.2012.6252544, 10.1109/IJCNN.2012.6252544]
[10]  
Gu SQ, 2018, PROCEEDINGS OF THE TWENTY-SEVENTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, P2177