Sensitive-Sample Fingerprinting of Deep Neural Networks

Sensitive-Sample Fingerprinting of Deep Neural Networks
复制标题

DOI:
10.1109/cvpr.2019.00486
复制
发表时间:
2019-06
期刊:
2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Zecheng He;Tianwei Zhang;R. Lee
Zecheng He;Tianwei Zhang;R. Lee
中科院分区:
其他
文献类型:
--
作者:
Zecheng He;Tianwei Zhang;R. Lee

文献摘要

被引文献

相似文献

提供了许多基于云的服务,以帮助客户开发和部署深度学习应用程序。当客户在云中部署深度学习模型并将其提供给最终用户时,重要的是能够验证所部署的模型没有被篡改。在本文中,我们提出了一种新颖而实用的方法来验证远程深度学习模型的完整性,只需黑盒访问目标模型。具体来说,我们定义了敏感样本指纹,这是一小部分人类不明显的转换输入,使模型输出对模型的参数敏感。即使是很小的模型变化也可以清楚地反映在模型输出中。对不同类型的模型完整性攻击的实验结果表明,我们提出的方法是有效的和高效的。它可以以高准确率(>99.95%)检测模型完整性漏洞,并保证对所有评估的攻击零误报。同时,与非敏感样本相比,它只需要多达103倍的模型推理。
Numerous cloud-based services are provided to help customers develop and deploy deep learning applications. When a customer deploys a deep learning model in the cloud and serves it to end-users, it is important to be able to verify that the deployed model has not been tampered with. In this paper, we propose a novel and practical methodology to verify the integrity of remote deep learning models, with only black-box access to the target models. Specifically, we define Sensitive-Sample fingerprints, which are a small set of human unnoticeable transformed inputs that make the model outputs sensitive to the model's parameters. Even small model changes can be clearly reflected in the model outputs. Experimental results on different types of model integrity attacks show that we proposed approach is both effective and efficient. It can detect model integrity breaches with high accuracy (>99.95%) and guaranteed zero false positives on all evaluated attacks. Meanwhile, it only requires up to 103X fewer model inferences, compared with non-sensitive samples.