PUF-based Edge DNN Model IP Protection with Self-obfuscation and Publicly Verifiable Ownership
Jingdong Jiang, Yue Zheng, Chip-Hong Chang · 2025
Intellectual Property (IP) violation poses severe threats to Deep Neural Network (DNN) models deployed on easily accessible edge devices for real-time, security- and saff1ety-critical applications. Existing DNN IP protection schemes lack consideration of hardware attack vectors and fall short of the security demands of edge DNNs. In this paper, we leverage hardware-software co-design for pre-emptive protection of DNN models implemented on edge devices against multiple field attacks. A unified credential is generated by projecting a subset of model's weights selected by the physical unclonable function of its hosting device into a random space spanned by its owner ID. The model is trained in such a way that the aff1ine parameters of selected normalization blocks are modulated by this credential to provide accurate inference on valid edge device and owner ID, which allows the ownership to be publicly and black-box verifiable by its users. The deployed inference machine lockdowns automatically upon any attempts to export, modify or retrain the model, thus effectively prevent many forms of infringement, including ownership forgery, model extraction and replication, unauthorized domain adaptation and reimplementation of model on unauthorized devices. We have evaluated these attacks and the ownership proof with two DNN models and four datasets. The experimental results demonstrated that the protected edge DNNs produce high inference fidelity on correct device and valid owner ID, and significantly degraded accuracy on all attacks.