Affiliation:
1. School of Big Data and Computer Science Guizhou Normal University Guiyang China
2. Engineering Laboratory for Applied Technology of Big Data in Education in Guizhou Guizhou Normal University Guiyang China
3. National Engineering Research Center of Big Data Application to The Improvement of Governance Capacity CETC Big Data Research Institute Co., Ltd. Guiyang China
Abstract
SummaryVarious deep neural network (DNN) model watermarks have been proposed by researchers to verify copyrights for deep neural networks DNN. However, most DNN watermarking methods cannot prevent attackers from stealing and using the model. Unlike many existing approaches, this paper uses a channel pruning algorithm to protect DNN models, which verifies DNN models copyrights but also prevents the illegal use of DNN models. In this work, the pruning threshold or pruning rate is used as the secret key of a DNN model. After the secret key is distributed to multiple users, they prune the DNN model with the secret key, and the pruned and fine‐tuned model is provided to the users. The users can verify ownership of the model according to the pruning accuracy and fine‐tuning accuracy. If the secret key is incorrect, the accuracy of the model after fine‐tuning will be very low, and users will be unable to use the reasoning function of the fine‐tuned model. Based on the CIFAR‐10 and CIFAR‐100 datasets, we conducted experiments on five popular DNN models. The experimental results show that we can authorize multiple users by pruning very few channels in the convolution layers of the DNN model.
Funder
National Natural Science Foundation of China
Subject
Computational Theory and Mathematics,Computer Networks and Communications,Computer Science Applications,Theoretical Computer Science,Software
Reference51 articles.
1. Deep learning
2. Multimedia Digital Rights Protection Using Watermarking Techniques
3. An adaptive watermarking technique for the copyright of digital images and digital image protection;Perwej Y;CoRR,2012
4. Copyright protection for digital image by watermarking technique;Ali SA;J Inf Process Syst,2017
5. Robust Digital Watermarking Techniques for Copyright Protection of Digital Data: A Survey
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献