ConNEF: An Encryption Framework for Deep Neural Network IP Protection

Lanjun Wang, Mingwang Hu, Shicheng Xu, Mengbiao Zhao, Jianlong Chang · 2025

In the era of Machine Learning as a Service (MLaaS), service providers upload pre-trained deep neural networks (DNNs) to the website of the MLaaS platform, allowing customers to purchase model usage rights. Due to the substantial amount of training data and computational resources consumed, pre-trained DNNs have become significant assets for service providers. To protect the intellectual property (IP) of DNNs, existing active authentication methods encrypt the models to prevent unauthorized usage. However, these methods face challenges such as insufficient generalization, high overhead, and weak robustness. This paper proposes a Confusion Neuron-based Encryption Framework (ConNEF), which encrypts DNN models with a small portion of confusion neurons. Extensive experiments demonstrate that ConNEF is compatible with various networks across vision and language tasks, and outperforms baseline methods in effectiveness, efficiency, and robustness.

Read the paper · More papers on PaperTik