English

A Protection against the Extraction of Neural Network Models

Machine Learning 2020-08-03 v3 Cryptography and Security Machine Learning

Abstract

Given oracle access to a Neural Network (NN), it is possible to extract its underlying model. We here introduce a protection by adding parasitic layers which keep the underlying NN's predictions mostly unchanged while complexifying the task of reverse-engineering. Our countermeasure relies on approximating a noisy identity mapping with a Convolutional NN. We explain why the introduction of new parasitic layers complexifies the attacks. We report experiments regarding the performance and the accuracy of the protected NN.

Keywords

Cite

@article{arxiv.2005.12782,
  title  = {A Protection against the Extraction of Neural Network Models},
  author = {Hervé Chabanne and Vincent Despiegel and Linda Guiga},
  journal= {arXiv preprint arXiv:2005.12782},
  year   = {2020}
}

Comments

Add Noisy Identity Parasitic layers