Proactive Intellectual Property Protection for Edge AI Models
摘要
With the advancement and widespread application of artificial intelligence, AI models have become a significant form of intellectual property. Due to their proximity to end users, edge platforms are more susceptible to physical and cyber attacks, which pose higher security risks and make AI models deployed on edge platforms particularly vulnerable to severe intellectual property threats. In this paper, we propose a novel proactive method for protecting the intellectual property of AI models tailored for edge intelligence, named SecureEI. This method draws upon the concept of model splitting and utilizes poisoned data for model training. Through our meticulously designed device-edge model collaborative training and weight adjustment techniques, we ensure that the well-trained model exhibits high accuracy exclusively on the license data, while demonstrating robust resistance to fine-tuning attacks. We evaluate SecureEI on datasets such as MNIST, CIFAR-10, and FaceScrub. The results indicate that, compared to the state-of-the-art methods in this field, SecureEI not only enhances model accuracy but also significantly improves the model’s resistance to fine-tuning attacks.