Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
97 tokens/sec
GPT-4o
53 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
5 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

InFIP: An Explainable DNN Intellectual Property Protection Method based on Intrinsic Features (2210.07481v1)

Published 14 Oct 2022 in cs.CV

Abstract: Intellectual property (IP) protection for Deep Neural Networks (DNNs) has raised serious concerns in recent years. Most existing works embed watermarks in the DNN model for IP protection, which need to modify the model and lack of interpretability. In this paper, for the first time, we propose an interpretable intellectual property protection method for DNN based on explainable artificial intelligence. Compared with existing works, the proposed method does not modify the DNN model, and the decision of the ownership verification is interpretable. We extract the intrinsic features of the DNN model by using Deep Taylor Decomposition. Since the intrinsic feature is composed of unique interpretation of the model's decision, the intrinsic feature can be regarded as fingerprint of the model. If the fingerprint of a suspected model is the same as the original model, the suspected model is considered as a pirated model. Experimental results demonstrate that the fingerprints can be successfully used to verify the ownership of the model and the test accuracy of the model is not affected. Furthermore, the proposed method is robust to fine-tuning attack, pruning attack, watermark overwriting attack, and adaptive attack.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (6)
  1. Mingfu Xue (19 papers)
  2. Xin Wang (1307 papers)
  3. Yinghao Wu (11 papers)
  4. Shifeng Ni (2 papers)
  5. Yushu Zhang (43 papers)
  6. Weiqiang Liu (18 papers)
Citations (2)

Summary

We haven't generated a summary for this paper yet.