Coded DNN Watermark: Robustness against Pruning Models Using Constant Weight Code

Coded DNN Watermark: Robustness against Pruning Models Using Constant Weight Code
复制标题

编码DNN水印:恒权编码对剪枝模型的鲁棒性

DOI:
10.3390/jimaging8060152
复制
发表时间:
2022-05-26
期刊:
影响因子:
3.2
通讯作者:
--
中科院分区:
其他
文献类型:
--
作者:

文献摘要

相似文献

深度神经网络(DNN)水印技术越来越多地用于保护DNN模型的知识产权。基本上,DNN水印是一种将边信息插入DNN模型中而不会显著降低其原始任务性能的技术。修剪攻击是DNN水印的一个威胁,其中模型中不太重要的神经元被修剪,以使其更快,更紧凑。因此,可以从DNN模型中移除水印。本文研究了一种保护DNN水印免受剪枝攻击的信道编码方法。信道模型完全不同于涉及数字图像的常规模型。确定DNN水印的合适编码方法仍然是一个悬而未决的问题。在此,我们提出了一种新的编码方法,使用恒定重量的代码来保护DNN水印免受修剪攻击。实验结果表明,通过对码字中的二进制符号设置两个阈值,可以控制对剪枝攻击的鲁棒性。
Deep Neural Network (DNN) watermarking techniques are increasingly being used to protect the intellectual property of DNN models. Basically, DNN watermarking is a technique to insert side information into the DNN model without significantly degrading the performance of its original task. A pruning attack is a threat to DNN watermarking, wherein the less important neurons in the model are pruned to make it faster and more compact. As a result, removing the watermark from the DNN model is possible. This study investigates a channel coding approach to protect DNN watermarking against pruning attacks. The channel model differs completely from conventional models involving digital images. Determining the suitable encoding methods for DNN watermarking remains an open problem. Herein, we presented a novel encoding approach using constant weight codes to protect the DNN watermarking against pruning attacks. The experimental results confirmed that the robustness against pruning attacks could be controlled by carefully setting two thresholds for binary symbols in the codeword.