Pith. sign in

REVIEW 1 cited by

Fingerprinting Deep Neural Networks Globally via Universal Adversarial Perturbations

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2202.08602 v3 pith:GNIYWT4V submitted 2022-02-17 cs.CR cs.AI

classification cs.CRcs.AI
keywords modelmodelsadversarialfingerprintingperturbationsproposestolensubspace
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

In this paper, we propose a novel and practical mechanism which enables the service provider to verify whether a suspect model is stolen from the victim model via model extraction attacks. Our key insight is that the profile of a DNN model's decision boundary can be uniquely characterized by its Universal Adversarial Perturbations (UAPs). UAPs belong to a low-dimensional subspace and piracy models' subspaces are more consistent with victim model's subspace compared with non-piracy model. Based on this, we propose a UAP fingerprinting method for DNN models and train an encoder via contrastive learning that takes fingerprint as inputs, outputs a similarity score. Extensive studies show that our framework can detect model IP breaches with confidence > 99.99 within only 20 fingerprints of the suspect model. It has good generalizability across different model architectures and is robust against post-modifications on stolen models.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Protecting Intellectual Property of EEG-based Neural Networks with Watermarking

    cs.LG 2025-02 reject novelty 5.0 of 10

    A wonder filter watermark derived from an owner's digital signature is embedded into EEG models, with experiments on DEAP claiming persistence through fine-tuning, transfer learning, and pruning.

Pith tools