Training DNN Model with Secret Key for Model Protection

Training DNN Model with Secret Key for Model Protection
复制标题

使用密钥训练 DNN 模型以保护模型

DOI:
10.1109/gcce50665.2020.9291813
复制
发表时间:
2020
期刊:
2020 IEEE 9th Global Conference on Consumer Electronics (GCCE)
影响因子:
--
通讯作者:
H. Kiya
H. Kiya
中科院分区:
--
文献类型:
--
作者:
April Pyone Maung Maung;H. Kiya

文献摘要

参考文献

被引文献

相似文献

在本文中,我们通过使用秘密键作为预处理技术来首次输入图像来提出一种模型保护方法。受保护的模型是通过使用此类预处理图像的训练来构建的。实验结果表明,当密钥正确时,受保护模型的性能接近非保护模型的性能,而当给出不正确的键时,精度会严重降低,并且提出的模型保护具有足够的鲁棒性,可以针对微调进行稳健。攻击,同时保持与使用非保护模型的性能精度几乎相同。
In this paper, we propose a model protection method by using block-wise pixel shuffling with a secret key as a preprocessing technique to input images for the first time. The protected model is built by training with such preprocessed images. Experiment results show that the performance of the protected model is close to that of non-protected models when the key is correct, while the accuracy is severely dropped when an incorrect key is given, and the proposed model protection has enough robustness against fine-tuning attacks, while maintaining almost the same performance accuracy as that of using a nonprotected model.
训练深度神经网络中隐藏水印的视觉解码
DOI: --
发表时间: 2019
期刊:
影响因子: --
作者:
Shigeyuki Sakazawa;Emi Myodo;Kazuyuki Tasaka;Hiromasa Yanagihara
通讯作者: Hiromasa Yanagihara