Intrinsic Examples: Robust Fingerprinting of Deep Neural Networks

Intrinsic Examples: Robust Fingerprinting of Deep Neural Networks
复制标题

DOI:
--
复制
发表时间:
2021
影响因子:
5.6
通讯作者:
Siyue Wang;Pu Zhao;Xiao Wang;S. Chin;T. Wahl;Yunsi Fei;Qi Alfred Chen;Xue Lin
Siyue Wang;Pu Zhao;Xiao Wang;S. Chin;T. Wahl;Yunsi Fei;Qi Alfred Chen;Xue Lin
中科院分区:
生物学2区
文献类型:
--
作者:
Siyue Wang;Pu Zhao;Xiao Wang;S. Chin;T. Wahl;Yunsi Fei;Qi Alfred Chen;Xue Lin

文献摘要

相似文献

本文提出使用内在示例作为DNN指纹技术,用于在边缘设备上实现的DNN模型的功能验证。所提出的固有示例不影响正常的DNN训练,并且可以实现封装到边缘设备应用中的DNN模型的黑盒测试能力。我们提供了三种算法,用于导出预训练模型(DNN系统设计和实现过程之前的模型)的内在示例,以检索从训练数据集中学习到的知识,用于检测系统实现过程中可能发生的对抗性第三方攻击,例如迁移学习和故障注入攻击。此外,由于系统设计人员使用的各种DNN模型压缩方法,它们可以适应模型转换。量化减少了权重的比特表示中的冗余[22,26,33]。利用k比特权重表示,量化将权重映射到总共2k个量化级别中。
This paper proposes to use intrinsic examples as a DNN fingerprinting technique for the functionality verification of DNN models implemented on edge devices. The proposed intrinsic examples do not affect the normal DNN training and can enable the black-box testing capability for DNN models packaged into edge device applications. We provide three algorithms for deriving intrinsic examples of the pre-trained model (the model before the DNN system design and implementation procedure) to retrieve the knowledge learnt from the training dataset for the detection of adversarial third-party attacks such as transfer learning and fault injection attack that may happen during the system implementation procedure. Besides, they can accommodate the model transformations due to various DNN model compression methods used by the system designer. quantization reduces redundancy in bit representation of weights [22, 26, 33]. With a k -bit weight representation, quantization maps weights into a total of 2 k quantized levels.