错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Data Security Protection Method for Deep Neural Network Model Based on Mobility and Sharing

  • Xinjian Zhao,
  • Qianmu Li,
  • Qi Wang,
  • Shi Chen,
  • Tengfei Li,
  • Nianzhe Li

摘要

With the rapid development of digital economy, numerous business scenarios, such as smart grid, energy network, intelligent transportation, etc., require the design and distribution of deep neural network (DNN) models, which typically use large amounts of data and computing resources for training. As a result, DNN models are now considered important assets, but at great risk of being stolen and distributed illegally. In response to the new risks and challenges brought by frequent data flow and sharing, watermarks have been introduced to protect the ownership of DNN models. Watermarks can be extracted in a relatively simple manner to declare ownership of a model. However, watermarks are vulnerable to attacks. In this work, we propose a novel label-based black-box watermark model protection algorithm. Inspired by new labels, we design a method to embed watermarks by adding new labels in the model, and to prevent watermarks from being forged, we use encryption algorithms to generate key samples. We conduct experiments on the VGG19 model using the CIFAR-10 dataset. Experimental results show that the method is robust to fine-tuning attacks, pruning attacks. Furthermore, our method does not affect the performance of deep neural network models. This method helps to solve scenarios such as “internal data circulation, external data sharing and multi-party data collaboration”.