Enhancing Intellectual Property Protection in Deep Neural Network with Confidential Computing

Wensheng Tian, Ruiyan Xia, Zhichao Yan, Panpan Tang, Yonggang Tu, Lei Zhang · 2022

Deep neural network(DNN) models consume a lot of computational resources in the training process, and DNN models have become an important intellectual property. The methods for DNN models protection are currently mainly based on digital watermarking. The protection technique based on digital watermarking can only passively verify deep neural networks, and cannot restrict the illegal distribution and use of deep learning models. If the deep neural network model is deployed on a public cloud platform, the watermarking-based approach does not prevent malicious administrators from stealing the model. We propose a protection method based on the confidential computing, which divides the deep neural network model into a data preprocessing model and a inference model, we use a confidential computing environment to protect the data preprocessing model, and the inference model can be distributed to authorized users for deployment, even if malicious users get the inference model or train student models through knowledge distillation, they cannot obtain the highly accurate results from their models. It is also experimentally demonstrated that the method is also able to resist knowledge migration from the model using fine-tuning training.

Read the paper · More papers on PaperTik