Characteristic Examples: High-Robustness, Low-Transferability Fingerprinting of Neural Networks

Characteristic Examples: High-Robustness, Low-Transferability Fingerprinting of Neural Networks
复制标题

DOI:
10.24963/ijcai.2021/80
复制
发表时间:
2021-08
期刊:
--
影响因子:
--
通讯作者:
Siyue Wang;Xiao Wang;Pin-Yu Chen;Pu Zhao;Xue Lin
Siyue Wang;Xiao Wang;Pin-Yu Chen;Pu Zhao;Xue Lin
中科院分区:
其他
文献类型:
--
作者:
Siyue Wang;Xiao Wang;Pin-Yu Chen;Pu Zhao;Xue Lin

文献摘要

相似文献

本文提出了有效识别深度神经网络的特征示例,其特点是对基础模型的高鲁棒性,以及对无关联模型的低可移植性。这是第一个同时考虑鲁棒性和可转移性来生成真实指纹的工作,而目前的方法缺乏实际的假设,可能会产生很大的假阳性率。为了在鲁棒性和可移植性之间实现更好的权衡,我们提出了三种特征示例:香草C示例,RC示例和LTRC示例,以从原始基础模型中获得指纹。为了公平地描述鲁棒性和可转移性之间的权衡,我们提出了Uniform Score,一个衡量鲁棒性和可转移性之间差异的综合指标,它也可以作为虚警问题的指标。大量的实验表明,所提出的特征的例子,可以实现上级的性能相比,现有的指纹方法。特别是,对于VGG ImageNet模型,使用LTRC-examples的唯一性得分比基线方法高4倍,并且不会产生任何误报。
This paper proposes Characteristic Examples for effectively fingerprinting deep neural networks, featuring high-robustness to the base model against model pruning as well as low-transferability to unassociated models. This is the first work taking both robustness and transferability into consideration for generating realistic fingerprints, whereas current methods lack practical assumptions and may incur large false positive rates. To achieve better trade-off between robustness and transferability, we propose three kinds of characteristic examples: vanilla C-examples, RC-examples, and LTRC-example, to derive fingerprints from the original base model. To fairly characterize the trade-off between robustness and transferability, we propose Uniqueness Score, a comprehensive metric that measures the difference between robustness and transferability, which also serves as an indicator to the false alarm problem. Extensive experiments demonstrate that the proposed characteristic examples can achieve superior performance when compared with existing fingerprinting methods. In particular, for VGG ImageNet models, using LTRC-examples gives 4X higher uniqueness score than the baseline method and does not incur any false positives.