English

High-Robustness, Low-Transferability Fingerprinting of Neural Networks

Machine Learning 2021-05-18 v1 Artificial Intelligence Cryptography and Security Computer Vision and Pattern Recognition

Abstract

This paper proposes Characteristic Examples for effectively fingerprinting deep neural networks, featuring high-robustness to the base model against model pruning as well as low-transferability to unassociated models. This is the first work taking both robustness and transferability into consideration for generating realistic fingerprints, whereas current methods lack practical assumptions and may incur large false positive rates. To achieve better trade-off between robustness and transferability, we propose three kinds of characteristic examples: vanilla C-examples, RC-examples, and LTRC-example, to derive fingerprints from the original base model. To fairly characterize the trade-off between robustness and transferability, we propose Uniqueness Score, a comprehensive metric that measures the difference between robustness and transferability, which also serves as an indicator to the false alarm problem.

Keywords

Cite

@article{arxiv.2105.07078,
  title  = {High-Robustness, Low-Transferability Fingerprinting of Neural Networks},
  author = {Siyue Wang and Xiao Wang and Pin-Yu Chen and Pu Zhao and Xue Lin},
  journal= {arXiv preprint arXiv:2105.07078},
  year   = {2021}
}

Comments

ICLR 2021 Workshop on Security and Safety in Machine Learning Systems