Towards Understanding and Enhancing Security of Proof-of-Training for DNN Model Ownership Verification

计算机科学 概念证明 业务 操作系统
作者
Yijia Chang,Hongchao Jiang,Chao Lin,Xinyi Huang,Jianping Weng
出处
期刊:Cornell University - arXiv [Cornell University]
标识
DOI:10.48550/arxiv.2410.04397
摘要

The great economic values of deep neural networks (DNNs) urge AI enterprises to protect their intellectual property (IP) for these models. Recently, proof-of-training (PoT) has been proposed as a promising solution to DNN IP protection, through which AI enterprises can utilize the record of DNN training process as their ownership proof. To prevent attackers from forging ownership proof, a secure PoT scheme should be able to distinguish honest training records from those forged by attackers. Although existing PoT schemes provide various distinction criteria, these criteria are based on intuitions or observations. The effectiveness of these criteria lacks clear and comprehensive analysis, resulting in existing schemes initially deemed secure being swiftly compromised by simple ideas. In this paper, we make the first move to identify distinction criteria in the style of formal methods, so that their effectiveness can be explicitly demonstrated. Specifically, we conduct systematic modeling to cover a wide range of attacks and then theoretically analyze the distinctions between honest and forged training records. The analysis results not only induce a universal distinction criterion, but also provide detailed reasoning to demonstrate its effectiveness in defending against attacks covered by our model. Guided by the criterion, we propose a generic PoT construction that can be instantiated into concrete schemes. This construction sheds light on the realization that trajectory matching algorithms, previously employed in data distillation, possess significant advantages in PoT construction. Experimental results demonstrate that our scheme can resist attacks that have compromised existing PoT schemes, which corroborates its superiority in security.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
yoqalux发布了新的文献求助10
刚刚
贺兰完成签到,获得积分10
1秒前
领导范儿应助YZQ采纳,获得10
1秒前
panpan完成签到,获得积分10
2秒前
2秒前
湫chun完成签到 ,获得积分10
3秒前
碎觉觉发布了新的文献求助10
3秒前
sougardenist完成签到 ,获得积分0
3秒前
刘星星完成签到 ,获得积分10
3秒前
4秒前
4秒前
Gauss完成签到,获得积分0
4秒前
火星上的菲鹰完成签到,获得积分0
5秒前
科研通AI6.2应助lili采纳,获得10
5秒前
小手冰凉完成签到 ,获得积分10
5秒前
天天快乐应助rjx采纳,获得10
6秒前
酷酷听荷完成签到,获得积分10
7秒前
vv发布了新的文献求助10
7秒前
9秒前
积极的猎豹完成签到,获得积分10
9秒前
852应助美满的灵安采纳,获得10
9秒前
着急的彩虹完成签到,获得积分10
9秒前
v0id应助科研通管家采纳,获得10
10秒前
cy发布了新的文献求助10
10秒前
Kao应助科研通管家采纳,获得10
10秒前
11秒前
华仔应助科研通管家采纳,获得10
11秒前
打打应助科研通管家采纳,获得10
11秒前
11秒前
Enigma_GEB应助科研通管家采纳,获得10
11秒前
CipherSage应助科研通管家采纳,获得10
11秒前
小白应助科研通管家采纳,获得10
11秒前
小白应助科研通管家采纳,获得10
12秒前
12秒前
Kao应助科研通管家采纳,获得10
12秒前
汉堡包应助伯赏满天采纳,获得10
12秒前
完美世界应助科研通管家采纳,获得10
13秒前
sagitar应助科研通管家采纳,获得20
13秒前
Valent应助科研通管家采纳,获得10
13秒前
yoqalux发布了新的文献求助10
14秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Health Psychology 800
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
Electric machines: theory, operating applications, and controls 500
The Analytical and Numerical Solution of Electric and Magnetic Fields 500
When Is Two-Stage Sample Robust Optimization Asymptotically Optimal? 500
Discerning Saints: Moralization of Intrinsic Motivation and Selective Prosociality at Work 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7593030
求助须知:如何正确求助?哪些是违规求助? 9170261
关于积分的说明 19627864
捐赠科研通 7170885
什么是DOI,文献DOI怎么找? 3267554
关于科研通互助平台的介绍 2432418
邀请新用户注册赠送积分活动 2260128