Hardware-Assisted Intellectual Property Protection of Deep Learning Models

Hardware-Assisted Intellectual Property Protection of Deep Learning Models
复制标题

深度学习模型的硬件辅助知识产权保护

DOI:
--
复制
发表时间:
2020
期刊:
Design Automation Conference
影响因子:
--
通讯作者:
Ankur Srivastava
Ankur Srivastava
中科院分区:
--
文献类型:
--
作者:
Abhishek Chakraborty;Ankit Mondal;Ankur Srivastava

文献摘要

被引文献

相似文献

对训练有素的深度学习(DL)模型的知识产权(IP)保护已成为一个主要问题,特别是随着机器学习即服务(MLaaS)部署的增长趋势。在这项工作中,我们展示了利用硬件根的信任,以保护潜在的攻击者可以访问的IP的DL模型。我们提出了一个名为硬件保护神经网络(HPNN)的混淆框架,其中深度神经网络根据密钥进行训练,然后将混淆的DL模型托管在公共模型共享平台上。该框架确保只有拥有可信硬件设备(具有嵌入在芯片上的密钥)的授权最终用户才能够使用发布的模型运行预期的DL应用程序。广泛的实验评估表明,任何未经授权的使用这种混淆的DL模型都会导致不同神经网络架构和基准数据集的准确率显著下降,从73.22%到80.17%不等。此外,我们还证明了所提出的HPNN框架对模型微调类型的攻击的鲁棒性。
The protection of intellectual property (IP) rights of well-trained deep learning (DL) models has become a matter of major concern, especially with the growing trend of deployment of Machine Learning as a Service (MLaaS). In this work, we demonstrate the utilization of a hardware root-of-trust to safeguard the IPs of such DL models which potential attackers have access to. We propose an obfuscation framework called Hardware Protected Neural Network (HPNN) in which a deep neural network is trained as a function of a secret key and then, the obfuscated DL model is hosted on a public model sharing platform. This framework ensures that only an authorized end-user who possesses a trustworthy hardware device (with the secret key embedded on-chip) is able to run intended DL applications using the published model. Extensive experimental evaluations show that any unauthorized usage of such obfuscated DL models result in significant accuracy drops ranging from 73.22 to 80.17% across different neural network architectures and benchmark datasets. In addition, we also demonstrate the robustness of proposed HPNN framework against a model fine-tuning type of attack.