Graph-based Robust Model Hashing
Yitong Tao, Chuan Qin · 2022
Deep neural networks (DNNs) intellectual property protection attracts extensive attention recently, and how to identify suspicious illegal copied version of original model is an important issue for protecting the profits of model owner. The existing techniques, such as model watermarking, are limited due to inevitable modifications to the models. In this paper, we propose a graph-based robust model hashing scheme that learns the compact hash representations of DNNs through processing comprehensive graph-level features. Thus, the hash distances between similar models are significantly smaller than those of dissimilar models, which can be utilized for model authentication. Specifically, model graph data is first constructed by analyzing the computational graph of the target model. Then, the graph-level features are extracted as non-linear substructures sets. After hash representation learning for the features, the target model can be represented as the hash code. Experimental results show that the proposed scheme is robust against different types of attacks on models, and can also achieve satisfactory performances of discrimination and generalizability.