Non-Transferable Learning: A New Approach for Model Ownership Verification and Applicability Authorization

Non-Transferable Learning: A New Approach for Model Ownership Verification and Applicability Authorization
复制标题

DOI:
--
复制
发表时间:
2021-06
期刊:
--
影响因子:
--
通讯作者:
Lixu Wang;Shichao Xu;Ruiqi Xu;Xiao Wang;Qi Zhu
Lixu Wang;Shichao Xu;Ruiqi Xu;Xiao Wang;Qi Zhu
中科院分区:
其他
文献类型:
--
作者:
Lixu Wang;Shichao Xu;Ruiqi Xu;Xiao Wang;Qi Zhu

文献摘要

被引文献

相似文献

随着人工智能即服务越来越受欢迎,保护训练有素的模型作为知识产权变得越来越重要。有两种常见的保护方法:所有权验证和使用授权。在本文中,我们提出了不可转移学习(NTL),一种新的方法,捕获学习模型中的排他性数据表示,并将模型泛化能力限制在某些领域。该方法为模型验证和授权提供了有效的解决方案。具体而言:1)对于所有权验证,通常使用水印技术,但通常易受复杂的水印去除方法的影响。相比之下,我们基于NTL的所有权验证对最先进的水印去除方法提供了强大的抵抗力,如在数字,CIFAR10&STL 10和VisDA数据集上使用6种去除方法的广泛实验所示。2)对于使用授权,现有的解决方案集中于授权特定用户访问模型,但授权用户仍然可以将模型应用于任何数据而不受限制。我们的基于NTL的授权方法提供了以数据为中心的保护,我们称之为适用性授权,这会显著降低模型在未经授权的数据上的性能。在上述数据集上的实验也表明了其有效性。
As Artificial Intelligence as a Service gains popularity, protecting well-trained models as intellectual property is becoming increasingly important. There are two common types of protection methods: ownership verification and usage authorization. In this paper, we propose Non-Transferable Learning (NTL), a novel approach that captures the exclusive data representation in the learned model and restricts the model generalization ability to certain domains. This approach provides effective solutions to both model verification and authorization. Specifically: 1) For ownership verification, watermarking techniques are commonly used but are often vulnerable to sophisticated watermark removal methods. By comparison, our NTL-based ownership verification provides robust resistance to state-of-the-art watermark removal methods, as shown in extensive experiments with 6 removal approaches over the digits, CIFAR10&STL10, and VisDA datasets. 2) For usage authorization, prior solutions focus on authorizing specific users to access the model, but authorized users can still apply the model to any data without restriction. Our NTL-based authorization approach instead provides data-centric protection, which we call applicability authorization, by significantly degrading the performance of the model on unauthorized data. Its effectiveness is also shown through experiments on the aforementioned datasets.