High-Robustness, Low-Transferability Fingerprinting of Neural Networks

High-Robustness, Low-Transferability Fingerprinting of Neural Networks
复制标题

DOI:
--
复制
发表时间:
2021-05
期刊:
ArXiv
影响因子:
--
通讯作者:
Siyue Wang;Xiao Wang;Pin-Yu Chen;Pu Zhao;Xue Lin
Siyue Wang;Xiao Wang;Pin-Yu Chen;Pu Zhao;Xue Lin
中科院分区:
其他
文献类型:
--
作者:
Siyue Wang;Xiao Wang;Pin-Yu Chen;Pu Zhao;Xue Lin

文献摘要

相似文献

本文提出了有效指纹识别深度神经网络的特征实例,具有对基本模型具有很强的抗模型剪枝能力,以及对非关联模型的低可转换性。这是第一个同时考虑稳健性和可转移性来生成真实指纹的工作,而目前的方法缺乏实用的假设,可能会导致很大的误检率。为了在健壮性和可移植性之间取得更好的折衷,我们提出了三种特征例子:普通的C-Example、RC-Example和LTRC-Example来从原始的基模型中提取指纹。为了更好地描述健壮性和可转移性之间的权衡,我们提出了唯一性评分,这是一种衡量健壮性和可转移性之间差异的综合度量,它也可以作为虚警问题的一个指标。
This paper proposes Characteristic Examples for effectively fingerprinting deep neural networks, featuring high-robustness to the base model against model pruning as well as low-transferability to unassociated models. This is the first work taking both robustness and transferability into consideration for generating realistic fingerprints, whereas current methods lack practical assumptions and may incur large false positive rates. To achieve better trade-off between robustness and transferability, we propose three kinds of characteristic examples: vanilla C-examples, RC-examples, and LTRC-example, to derive fingerprints from the original base model. To fairly characterize the trade-off between robustness and transferability, we propose Uniqueness Score, a comprehensive metric that measures the difference between robustness and transferability, which also serves as an indicator to the false alarm problem.