论文标题

培训DNN模型,具有秘密钥匙以进行模型保护

Training DNN Model with Secret Key for Model Protection

论文作者

AprilPyone, MaungMaung, Kiya, Hitoshi

论文摘要

在本文中,我们通过使用秘密键作为预处理技术来首次输入图像来提出一种模型保护方法。受保护的模型是通过使用此类预处理图像的训练来构建的。实验结果表明,当密钥正确时,受保护模型的性能接近非保护模型的性能,而当给出错误的键时,精度会严重降低,并且提出的模型保护不仅是对不仅野蛮的攻击,而且还具有微调攻击,同时保持与使用未经保护模型的相同性能的精确性。

In this paper, we propose a model protection method by using block-wise pixel shuffling with a secret key as a preprocessing technique to input images for the first time. The protected model is built by training with such preprocessed images. Experiment results show that the performance of the protected model is close to that of non-protected models when the key is correct, while the accuracy is severely dropped when an incorrect key is given, and the proposed model protection is robust against not only brute-force attacks but also fine-tuning attacks, while maintaining almost the same performance accuracy as that of using a non-protected model.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源