Find the Lady: Permutation and Re-Synchronization of Deep Neural Networks (2312.14182v1)
Abstract: Deep neural networks are characterized by multiple symmetrical, equi-loss solutions that are redundant. Thus, the order of neurons in a layer and feature maps can be given arbitrary permutations, without affecting (or minimally affecting) their output. If we shuffle these neurons, or if we apply to them some perturbations (like fine-tuning) can we put them back in the original order i.e. re-synchronize? Is there a possible corruption threat? Answering these questions is important for applications like neural network white-box watermarking for ownership tracking and integrity verification. We advance a method to re-synchronize the order of permuted neurons. Our method is also effective if neurons are further altered by parameter pruning, quantization, and fine-tuning, showing robustness to integrity attacks. Additionally, we provide theoretical and practical evidence for the usual means to corrupt the integrity of the model, resulting in a solution to counter it. We test our approach on popular computer vision datasets and models, and we illustrate the threat and our countermeasure on a popular white-box watermarking method.
- Turning Your Weakness into a Strength: Watermarking Deep Neural Networks by Backdooring. In 27th USENIX Security Symposium.
- Neural Networks with a Redundant Representation: Detecting the Undetectable. Physical review letters.
- Deepmarks: A Secure Fingerprinting Framework for Digital Rights Management of Deep Learning Models. In Proceedings of the 2019 on International Conference on Multimedia Retrieval.
- Encoder-Decoder with Atrous Separable Convolution for Semantic Image Segmentation. In Proceedings of the European conference on computer vision.
- Drop an Octave: Reducing Spatial Redundancy in Convolutional Neural Networks with Octave Convolution. In Proceedings of the IEEE/CVF International Conference on Computer Vision.
- The Cityscapes Dataset for Semantic Urban Scene Understanding. In Proceedings of the IEEE conference on computer vision and pattern recognition.
- A Hitchhiker’s Guide to White-Box Neural Network Watermarking Robustness. In 11th European Workshop on Visual Information Processing.
- An Image Is Worth 16x16 Words: Transformers for Image Recognition at Scale. In International Conference on Learning Representations.
- Property Inference Attacks on Fully Connected Neural Networks Using Permutation Invariant Representations. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security.
- Deep Residual Learning for Image Recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition.
- Hecht-Nielsen, R. 1990. On the Algebraic Structure of Feedforward Network Weight Spaces. In Advanced Neural Computers. Elsevier.
- Searching for MobilenetV3. In Proceedings of the IEEE/CVF international conference on computer vision.
- ultralytics/yolov5: v6.2 - YOLOv5 Classification Models, Apple M1, Reproducibility, ClearML and Deci.ai integrations.
- Learning Multiple Layers of Features from Tiny Images.
- Octree Guided CNN with Spherical Kernels for 3D Point Clouds. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition.
- Fostering the Robustness of White-Box Deep Neural Network Watermarks by Neuron Alignment. In ICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing. IEEE.
- A Survey of Deep Neural Network Watermarking Techniques. Neurocomputing.
- Microsoft COCO: Common Objects in Context. In European conference on computer vision. Springer.
- DVC: An End-to-End Deep Video Compression Framework. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition.
- UVG Dataset: 50/120fps 4K Sequences for Video Codec Analysis and Development. In Proceedings of the 11th ACM Multimedia Systems Conference.
- ImageNet Large Scale Visual Recognition Challenge. International Journal of Computer Vision.
- Neural-Network Feature Selector. IEEE transactions on neural networks.
- Very Deep Convolutional Networks for Large-Scale Image Recognition. Computing Research Repository.
- Dropout: A Simple Way to Prevent Neural Networks from Overfitting. The journal of machine learning research.
- A Deep-Dream Virtual Reality Platform for Studying Altered Perceptual Phenomenology. Scientific reports.
- Serene: Sensitivity-Based Regularization of Neurons for Structured Sparsity in Neural Networks. IEEE Transactions on Neural Networks and Learning Systems.
- Delving in the Loss Landscape to Embed Robust Watermarks into Neural Networks. In 25th International Conference on Pattern Recognition. IEEE.
- Embedding Watermarks into Deep Neural Networks. In Proceedings of the 2017 ACM on international conference on multimedia retrieval.
- A Comprehensive Survey on Robust Image Watermarking. Neurocomputing.
- Convolutional Neural Network Pruning with Structural Redundancy Reduction. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition.
Paper Prompts
Sign up for free to create and run prompts on this paper using GPT-5.
Top Community Prompts
Collections
Sign up for free to add this paper to one or more collections.