Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
119 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Fingerprinting Deep Neural Networks Globally via Universal Adversarial Perturbations (2202.08602v3)

Published 17 Feb 2022 in cs.CR and cs.AI

Abstract: In this paper, we propose a novel and practical mechanism which enables the service provider to verify whether a suspect model is stolen from the victim model via model extraction attacks. Our key insight is that the profile of a DNN model's decision boundary can be uniquely characterized by its Universal Adversarial Perturbations (UAPs). UAPs belong to a low-dimensional subspace and piracy models' subspaces are more consistent with victim model's subspace compared with non-piracy model. Based on this, we propose a UAP fingerprinting method for DNN models and train an encoder via contrastive learning that takes fingerprint as inputs, outputs a similarity score. Extensive studies show that our framework can detect model IP breaches with confidence > 99.99 within only 20 fingerprints of the suspect model. It has good generalizability across different model architectures and is robust against post-modifications on stolen models.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (6)
  1. Zirui Peng (4 papers)
  2. Shaofeng Li (16 papers)
  3. Guoxing Chen (10 papers)
  4. Cheng Zhang (388 papers)
  5. Haojin Zhu (16 papers)
  6. Minhui Xue (72 papers)
Citations (58)

Summary

We haven't generated a summary for this paper yet.