English
Related papers

Related papers: Solving the Capsulation Attack against Backdoor-ba…

200 papers

Deep neural networks (DNNs) deployed in a cloud often allow users to query models via the APIs. However, these APIs expose the models to model extraction attacks (MEAs). In this attack, the attacker attempts to duplicate the target model by…

Cryptography and Security · Computer Science 2025-06-26 Satoru Koda , Ikuya Morikawa

Deep neural network (DNN) with the state of art performance has emerged as a viable and lucrative business service. However, those impressive performances require a large number of computational resources, which comes at a high cost for the…

Computer Vision and Pattern Recognition · Computer Science 2019-11-20 XiangRui Xu , YaQin Li , Cao Yuan

Watermarking deep neural network (DNN) models has attracted a great deal of attention and interest in recent years because of the increasing demand to protect the intellectual property of DNN models. Many practical algorithms have been…

Cryptography and Security · Computer Science 2025-01-14 Chaoyue Huang , Hanzhou Wu

The huge supporting training data on the Internet has been a key factor in the success of deep learning models. However, this abundance of public-available data also raises concerns about the unauthorized exploitation of datasets for…

Cryptography and Security · Computer Science 2023-04-11 Ruixiang Tang , Qizhang Feng , Ninghao Liu , Fan Yang , Xia Hu

Watermarking is an essential technique for embedding an identifier (i.e., watermark message) within digital images to assert ownership and monitor unauthorized alterations. In face recognition systems, watermarking plays a pivotal role in…

Computer Vision and Pattern Recognition · Computer Science 2024-09-25 Yuguang Yao , Anil Jain , Sijia Liu

Recently, numerous highly-valuable Deep Neural Networks (DNNs) have been trained using deep learning algorithms. To protect the Intellectual Property (IP) of the original owners over such DNN models, backdoor-based watermarks have been…

Cryptography and Security · Computer Science 2024-01-30 Peizhuo Lv , Hualong Ma , Kai Chen , Jiachen Zhou , Shengzhi Zhang , Ruigang Liang , Shenchen Zhu , Pan Li , Yingjun Zhang

The intellectual property (IP) of Deep neural networks (DNNs) can be easily ``stolen'' by surrogate model attack. There has been significant progress in solutions to protect the IP of DNN models in classification tasks. However, little…

Cryptography and Security · Computer Science 2021-08-06 Jie Zhang , Dongdong Chen , Jing Liao , Han Fang , Zehua Ma , Weiming Zhang , Gang Hua , Nenghai Yu

Watermarking combines an imperceptible change to an input image that will trigger a detector, to assert provenance and protect intellectual property. The literature has shown great interest in attacks on watermarking schemes: attackers are…

Cryptography and Security · Computer Science 2026-05-19 Maria Bulychev , Neil G. Marchant , Benjamin I. P. Rubinstein

Despite the tremendous success, deep neural networks are exposed to serious IP infringement risks. Given a target deep model, if the attacker knows its full information, it can be easily stolen by fine-tuning. Even if only its output is…

Computer Vision and Pattern Recognition · Computer Science 2021-03-09 Jie Zhang , Dongdong Chen , Jing Liao , Weiming Zhang , Huamin Feng , Gang Hua , Nenghai Yu

The wide application of deep learning techniques is boosting the regulation of deep learning models, especially deep neural networks (DNN), as commercial products. A necessary prerequisite for such regulations is identifying the owner of…

Cryptography and Security · Computer Science 2021-12-30 Fang-Qi Li , Shi-Lin Wang , Yun Zhu

Engineering a top-notch deep learning model is an expensive procedure that involves collecting data, hiring human resources with expertise in machine learning, and providing high computational resources. For that reason, deep learning…

Machine Learning · Computer Science 2021-03-08 Omid Aramoon , Pin-Yu Chen , Gang Qu

With the increasing adoption of deep learning in speaker verification, large-scale speech datasets have become valuable intellectual property. To audit and prevent the unauthorized usage of these valuable released datasets, especially in…

Cryptography and Security · Computer Science 2025-04-08 Yiming Li , Kaiying Yan , Shuo Shao , Tongqing Zhai , Shu-Tao Xia , Zhan Qin , Dacheng Tao

Backdoor data poisoning is an emerging form of adversarial attack usually against deep neural network image classifiers. The attacker poisons the training set with a relatively small set of images from one (or several) source class(es),…

Machine Learning · Computer Science 2020-10-16 Zhen Xiang , David J. Miller , George Kesidis

With the wide application of deep neural networks, it is important to verify a host's possession over a deep neural network model and protect the model. To meet this goal, various mechanisms have been designed. By embedding extra…

Cryptography and Security · Computer Science 2021-07-19 Fang-Qi Li , Shi-Lin Wang , Alan Wee-Chung Liew

Model watermarking techniques can embed watermark information into the protected model for ownership declaration by constructing specific input-output pairs. However, existing watermarks are easily removed when facing model stealing…

Cryptography and Security · Computer Science 2025-11-13 Yunfei Yang , Xiaojun Chen , Yuexin Xuan , Zhendong Zhao , Xin Zhao , He Li

Backdoor attacks are emerging threats to deep neural networks, which typically embed malicious behaviors into a victim model by injecting poisoned samples. Adversaries can activate the injected backdoor during inference by presenting the…

Cryptography and Security · Computer Science 2025-12-05 Bingyin Zhao , Yingjie Lao

Deep neural networks have been demonstrated to be vulnerable to backdoor attacks. Specifically, by injecting a small number of maliciously constructed inputs into the training set, an adversary is able to plant a backdoor into the trained…

Machine Learning · Statistics 2019-12-10 Alexander Turner , Dimitris Tsipras , Aleksander Madry

Training a high-performance deep neural network requires large amounts of data and computational resources. Protecting the intellectual property (IP) and commercial ownership of a deep model is challenging yet increasingly crucial. A major…

Computer Vision and Pattern Recognition · Computer Science 2024-03-13 Shuyang Yu , Junyuan Hong , Haobo Zhang , Haotao Wang , Zhangyang Wang , Jiayu Zhou

As a valuable digital product, deep neural networks (DNNs) face increasingly severe threats to the intellectual property, making it necessary to develop effective technical measures to protect them. Trigger-based watermarking methods…

Cryptography and Security · Computer Science 2025-10-27 Chaoyue Huang , Gejian Zhao , Hanzhou Wu , Zhihua Xia , Asad Malik

The rapid proliferation of deep neural networks (DNNs) across several domains has led to increasing concerns regarding intellectual property (IP) protection and model misuse. Trained DNNs represent valuable assets, often developed through…

Cryptography and Security · Computer Science 2026-03-17 Sangeeth B , Serena Nicolazzo , Deepa K. , Vinod P