A protection method of trained CNN model with a secret key from unauthorized access

A protection method of trained CNN model with a secret key from unauthorized access
复制标题

一种使用密钥保护经过训练的 CNN 模型免遭未经授权访问的方法

DOI:
10.1017/atsip.2021.9
复制
发表时间:
2021
影响因子:
3.2
通讯作者:
Kiya Hitoshi
Kiya Hitoshi
中科院分区:
--
文献类型:
--
作者:
Maungmaung AprilPyone;Kiya Hitoshi

文献摘要

参考文献

被引文献

相似文献

在本文中,我们提出了一种使用密钥集保护卷积神经网络模型的新方法,以便没有正确密钥集的未经授权的用户无法访问经过训练的模型。该方法使我们不仅能够防止版权侵权,而且能够保护模型的功能免遭未经授权的访问,而无需任何明显的开销。我们引入了三种带有密钥集的分块变换来生成可学习的变换图像:像素改组、负/正变换和基于 Feistel 的格式保留加密。受保护的模型是使用转换后的图像进行训练的。 CIFAR和ImageNet数据集的实验结果表明,当密钥集正确时,受保护模型的性能接近于未受保护模型的性能,而当给出不正确的密钥集时,准确性严重下降。受保护的模型还被证明能够抵御各种攻击。与最先进的护照模型保护相比,所提出的方法在网络中没有任何额外的层,因此在训练和推理过程中没有任何开销。
In this paper, we propose a novel method for protecting convolutional neural network models with a secret key set so that unauthorized users without the correct key set cannot access trained models. The method enables us to protect not only from copyright infringement but also the functionality of a model from unauthorized access without any noticeable overhead. We introduce three block-wise transformations with a secret key set to generate learnable transformed images: pixel shuffling, negative/positive transformation, and format-preserving Feistel-based encryption. Protected models are trained by using transformed images. The results of experiments with the CIFAR and ImageNet datasets show that the performance of a protected model was close to that of non-protected models when the key set was correct, while the accuracy severely dropped when an incorrect key set was given. The protected model was also demonstrated to be robust against various attacks. Compared with the state-of-the-art model protection with passports, the proposed method does not have any additional layers in the network, and therefore, there is no overhead during training and inference processes.
使用适应网络的分块加扰图像识别
DOI: --
发表时间: 2020
期刊: arXiv.org
影响因子: --
作者:
Koki Madono;Masayuki Tanaka;M. Onishi;T. Ogawa
通讯作者: T. Ogawa
使用密钥训练 DNN 模型以保护模型
DOI: 10.1109/gcce50665.2020.9291813
发表时间: 2020
期刊: 2020 IEEE 9th Global Conference on Consumer Electronics (GCCE)
影响因子: --
作者:
April Pyone Maung Maung;H. Kiya
通讯作者: H. Kiya
训练深度神经网络中隐藏水印的视觉解码
DOI: --
发表时间: 2019
期刊:
影响因子: --
作者:
Shigeyuki Sakazawa;Emi Myodo;Kazuyuki Tasaka;Hiromasa Yanagihara
通讯作者: Hiromasa Yanagihara
DOI: 10.1109/tifs.2018.2881677
发表时间: 2019-06-01
影响因子: 6.8
作者:
Chuman, Tatsuya;Sirichotedumrong, Warit;Kiya, Hitoshi
通讯作者: Kiya, Hitoshi