Given oracle access to a Neural Network (NN), it is possible to extract its underlying model. We here introduce a protection by adding parasitic layers which keep the underlying NN's predictions mostly unchanged while complexifying the task of reverse-engineering. Our countermeasure relies on approximating a noisy identity mapping with a Convolutional NN. We explain why the introduction of new parasitic layers complexifies the attacks. We report experiments regarding the performance and the accuracy of the protected NN.
@article{arxiv.2005.12782,
title = {A Protection against the Extraction of Neural Network Models},
author = {Hervé Chabanne and Vincent Despiegel and Linda Guiga},
journal= {arXiv preprint arXiv:2005.12782},
year = {2020}
}