DeepHardMark: Towards Watermarking Neural Network Hardware
DeepHardMark: Towards Watermarking Neural Network Hardware
复制标题
DOI:
10.1609/aaai.v36i4.20367
复制
发表时间:
2022-06
期刊:
影响因子:
--
通讯作者:
Joseph Clements;Yingjie Lao
中科院分区:
文献类型:
--
作者:
Joseph Clements;Yingjie Lao
This paper presents a framework for embedding watermarks into DNN hardware accelerators. Unlike previous works that have looked at protecting the algorithmic intellectual properties of deep learning systems, this work proposes a methodology for defending deep learning hardware. Our methodology embeds modifications into the hardware accelerator's functional blocks that can be revealed with the rightful owner's key DNN and corresponding key sample, verifying the legitimate owner. We propose an Lp-box ADMM based algorithm to co-optimize watermark's hardware overhead and impact on the design's algorithmic functionality. We evaluate the performance of the hardware watermarking scheme on popular image classifier models using various accelerator designs. Our results demonstrate that the proposed methodology effectively embeds watermarks while preserving the original functionality of the hardware architecture. Specifically, we can successfully embed watermarks into the deep learning hardware and reliably execute a ResNet ImageNet classifiers with an accuracy degradation of only 0.009%