Mitigating Query-based Neural Network Fingerprinting via Data Augmentation

Meiqi Wang, Han Qiu, Tianwei Zhang, Meikang Qiu, Bhavani M. Thuraisingham · ACM Transactions on Sensor Networks · 2023

Protecting the intellectual property (IP) of deep neural network (DNN) models becomes essential and urgent with the rapidly increasing cost of DNN training. Fingerprinting is one promising IP protection method that queries suspicious models with specific fingerprint samples to infer and verify IP by comparing the predictions with pre-defined labels. Based on utilizing unique features of target models, various DNN fingerprinting methods are proposed to effectively verify the IP of models remotely with a meager false-positive ratio. In this paper, we propose a novel attack to mitigate query-based fingerprinting methods based on data augmentation methods. We propose a randomized transformation on input samples to significantly mislead the fingerprint samples’ prediction and compromise the IP verification. Then, our attack can keep the model utility with an acceptable accuracy drop in the data-free scenario (i.e. without any samples) or achieve much higher precision in the data-limited scenario (i.e. with a small number of samples with the same distribution). An intensive evaluation of three well-known model structures and three well-known datasets shows that our attack can effectively mitigate five query-based DNN fingerprinting methods in top-tier conferences.

Read the paper · More papers on PaperTik