vix.ing · top · new · best · stats

Fingerprinting Deep Neural Networks Globally via Universal Adversarial Perturbations

2022/02/17 by Zirui Peng, Shaofeng Li, Peng, Zirui +9 · 10 citations
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Artificial Intelligence (cs.AI) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #cs.AI #cs.CR

paper · pdf · doi:10.48550/arxiv.2202.08602

Accepted to CVPR 2022 (Oral Presentation)

openalex publication_date 2022/02/17 · openalex created_date 2022/05/05 · arxiv created 2022/05/08 · arxiv updated 2022/05/10 · openalex updated_date 2026/07/28

Abstract

In this paper, we propose a novel and practical mechanism which enables the service provider to verify whether a suspect model is stolen from the victim model via model extraction attacks. Our key insight is that the profile of a DNN model's decision boundary can be uniquely characterized by its Universal Adversarial Perturbations (UAPs). UAPs belong to a low-dimensional subspace and piracy models' subspaces are more consistent with victim model's subspace compared with non-piracy model. Based on this, we propose a UAP fingerprinting method for DNN models and train an encoder via contrastive learning that takes fingerprint as inputs, outputs a similarity score. Extensive studies show that our framework can detect model IP breaches with confidence > 99.99 within only 20 fingerprints of the suspect model. It has good generalizability across different model architectures and is robust against post-modifications on stolen models.

Cited by

Related