Neural Networks are used in various fields such as research and development. Because it takes much time and cost to make high-performance models, we tune a trained model in order to make the model for our purpose more efficiently. Hence, it is important to share high-performance trained models for the development of AI technologies. In such cases, it is important to protect its ownership. In this paper, we propose a method of protecting ownership of trained DNN models by using zero-knowledge proofs. Our scope is protecting white box models whose algorithms and parameters are completely open. Our proposal does not impair the performance of the models because no additional training and parameters are required. By our proposal, adversaries who know our proposal can not forge ownership and the owners can claim ownership multiple times. In the security analysis, we show the successful probability that adversaries can spoof as the owners for two attack scenarios. We also show the false positive rate for the unrelated model when the owners verify ownership of the unrelated model.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Protecting Ownership of Trained DNN Models with Zero-Knowledge Proofs

  • Shungo Sato,
  • Hidema Tanaka

摘要

Neural Networks are used in various fields such as research and development. Because it takes much time and cost to make high-performance models, we tune a trained model in order to make the model for our purpose more efficiently. Hence, it is important to share high-performance trained models for the development of AI technologies. In such cases, it is important to protect its ownership. In this paper, we propose a method of protecting ownership of trained DNN models by using zero-knowledge proofs. Our scope is protecting white box models whose algorithms and parameters are completely open. Our proposal does not impair the performance of the models because no additional training and parameters are required. By our proposal, adversaries who know our proposal can not forge ownership and the owners can claim ownership multiple times. In the security analysis, we show the successful probability that adversaries can spoof as the owners for two attack scenarios. We also show the false positive rate for the unrelated model when the owners verify ownership of the unrelated model.