Watermarking Deep Neural Networks for Embedded Systems

Deep neural networks (DNNs) have become an important tool for bringing intelligence to mobile and embedded devices. The increasingly wide deployment, sharing and potential commercialization of DNN models create a compelling need for intellectual property (IP) protection. Recently, DNN watermarking e...

Celý popis

Uloženo v:
Podrobná bibliografie
Vydáno v:2018 IEEE/ACM International Conference on Computer-Aided Design (ICCAD) s. 1 - 8
Hlavní autoři: Guo, Jia, Potkonjak, Miodrag
Médium: Konferenční příspěvek
Jazyk:angličtina
Vydáno: ACM 01.11.2018
Témata:
ISSN:1558-2434
On-line přístup:Získat plný text
Tagy: Přidat tag
Žádné tagy, Buďte první, kdo vytvoří štítek k tomuto záznamu!
Abstract Deep neural networks (DNNs) have become an important tool for bringing intelligence to mobile and embedded devices. The increasingly wide deployment, sharing and potential commercialization of DNN models create a compelling need for intellectual property (IP) protection. Recently, DNN watermarking emerges as a plausible IP protection method. Enabling DNN watermarking on embedded devices in a practical setting requires a black-box approach. Existing DNN watermarking frameworks either fail to meet the black-box requirement or are susceptible to several forms of attacks. We propose a watermarking framework by incorporating the author's signature in the process of training DNNs. While functioning normally in regular cases, the resulting watermarked DNN behaves in a different, predefined pattern when given any signed inputs, thus proving the authorship. We demonstrate an example implementation of the framework on popular image classification datasets and show that strong watermarks can be embedded in the models.
AbstractList Deep neural networks (DNNs) have become an important tool for bringing intelligence to mobile and embedded devices. The increasingly wide deployment, sharing and potential commercialization of DNN models create a compelling need for intellectual property (IP) protection. Recently, DNN watermarking emerges as a plausible IP protection method. Enabling DNN watermarking on embedded devices in a practical setting requires a black-box approach. Existing DNN watermarking frameworks either fail to meet the black-box requirement or are susceptible to several forms of attacks. We propose a watermarking framework by incorporating the author's signature in the process of training DNNs. While functioning normally in regular cases, the resulting watermarked DNN behaves in a different, predefined pattern when given any signed inputs, thus proving the authorship. We demonstrate an example implementation of the framework on popular image classification datasets and show that strong watermarks can be embedded in the models.
Author Potkonjak, Miodrag
Guo, Jia
Author_xml – sequence: 1
  givenname: Jia
  surname: Guo
  fullname: Guo, Jia
  organization: Computer Science Department, University of California, Los Angeles
– sequence: 2
  givenname: Miodrag
  surname: Potkonjak
  fullname: Potkonjak, Miodrag
  organization: Computer Science Department, University of California, Los Angeles
BookMark eNotjk1Lw0AURUdRsK1du3CTP5D65s1nllJbFYouVFyWSeaNxDZJmYlI_70jurkH7oHLnbKzfuiJsSsOC86luhEowWi1-KXVeMKmuQWhKgXmlE24UrZEKeQFm6f0CQBoDc96wvS7Gyl2Lu7a_qO4IzoUT_QV3T5j_B7iLhVhiMWqq8l78sXLMY3UpUt2Htw-0fyfM_a2Xr0uH8rN8_3j8nZTOpRmLBGF5DUFMBiMBxDW11CRwMZjgxRycqubqm6CIS2Dddr7bIWSxtdOiBm7_tttiWh7iG1-etxaZY2RSvwAk8NHUA
ContentType Conference Proceeding
DBID 6IE
6IH
CBEJK
RIE
RIO
DOI 10.1145/3240765.3240862
DatabaseName IEEE Electronic Library (IEL) Conference Proceedings
IEEE Proceedings Order Plan (POP) 1998-present by volume
IEEE Xplore All Conference Proceedings
IEEE Electronic Library (IEL)
IEEE Proceedings Order Plans (POP) 1998-present
DatabaseTitleList
Database_xml – sequence: 1
  dbid: RIE
  name: IEEE Electronic Library (IEL)
  url: https://ieeexplore.ieee.org/
  sourceTypes: Publisher
DeliveryMethod fulltext_linktorsrc
Discipline Engineering
EISBN 1450359507
9781450359504
EISSN 1558-2434
EndPage 8
ExternalDocumentID 8587745
Genre orig-research
GroupedDBID 123
6IE
6IF
6IH
6IL
6IN
AAWTH
ABLEC
ADZIZ
ALMA_UNASSIGNED_HOLDINGS
APO
BEFXN
BFFAM
BGNUA
BKEBE
BPEOZ
CBEJK
CHZPO
FEDTE
IEGSK
IJVOP
M43
OCL
RIE
RIL
RIO
ID FETCH-LOGICAL-a247t-22341bef072f7d0038db09e32cd2c2efd2c186c9bcf7e64f8a6dd32c3547dba33
IEDL.DBID RIE
ISICitedReferencesCount 110
ISICitedReferencesURI http://www.webofscience.com/api/gateway?GWVersion=2&SrcApp=Summon&SrcAuth=ProQuest&DestLinkType=CitingArticles&DestApp=WOS_CPL&KeyUT=000494640800131&url=https%3A%2F%2Fcvtisr.summon.serialssolutions.com%2F%23%21%2Fsearch%3Fho%3Df%26include.ft.matches%3Dt%26l%3Dnull%26q%3D
IngestDate Wed Aug 27 02:56:49 EDT 2025
IsPeerReviewed false
IsScholarly true
Language English
LinkModel DirectLink
MergedId FETCHMERGED-LOGICAL-a247t-22341bef072f7d0038db09e32cd2c2efd2c186c9bcf7e64f8a6dd32c3547dba33
PageCount 8
ParticipantIDs ieee_primary_8587745
PublicationCentury 2000
PublicationDate 2018-Nov.
PublicationDateYYYYMMDD 2018-11-01
PublicationDate_xml – month: 11
  year: 2018
  text: 2018-Nov.
PublicationDecade 2010
PublicationTitle 2018 IEEE/ACM International Conference on Computer-Aided Design (ICCAD)
PublicationTitleAbbrev ICCAD
PublicationYear 2018
Publisher ACM
Publisher_xml – name: ACM
SSID ssj0002871359
ssj0020286
Score 2.5114572
Snippet Deep neural networks (DNNs) have become an important tool for bringing intelligence to mobile and embedded devices. The increasingly wide deployment, sharing...
SourceID ieee
SourceType Publisher
StartPage 1
SubjectTerms ACM Reference format
Cloud computing
deep neural networks
Embedded systems
Neural networks
Software algorithms
Watermarking
Title Watermarking Deep Neural Networks for Embedded Systems
URI https://ieeexplore.ieee.org/document/8587745
WOSCitedRecordID wos000494640800131&url=https%3A%2F%2Fcvtisr.summon.serialssolutions.com%2F%23%21%2Fsearch%3Fho%3Df%26include.ft.matches%3Dt%26l%3Dnull%26q%3D
hasFullText 1
inHoldings 1
isFullTextHit
isPrint
link http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwlV1JT0IxEJ4A8aAXFzDu6cGjhUf3d1aIB0M4uHAjXeYlJgqExd9vW17QgxcvbdNJmi7JfNNp5xuAWy60kYZ5qjkqGhG_oFaXgYogjY9CpXNuwNcnPRqZyaQcN-BuFwuDiPnzGXZTM7_lh7nfJFdZL44arRXZhKbWahurtfOnJMufJ2iuL1uxQ9VUPn0he4l3TivZTbVJqXF-5VLJUDI8_N8kjqDzE5NHxju0OYYGzk7g4BedYBvUm82KNru_yQPigiTuDfsRq_zZe0WiiUoGnw6jugmkZivvwMtw8Hz_SOu8CNQyodc0IrroO6wKzSod0ttecEWJnPnAPMMqln2jfOl8pVGJylgVQpRyKXRwlvNTaM3mMzwDgpYlisAQ76ROOFE4ZSovXJAlutJ6dg7ttAPTxZb6Ylov_uLv7kvYj_aE2YbqXUFrvdzgNez5r_X7anmTz-sb-0uU0w
linkProvider IEEE
linkToHtml http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwlV1JT0IxEJ4gmqgXFzTu9uDRB4--bu-sEIxIOKByI13mJSYKhMXfb1tekIMXL23TSZouyXzTaecbgLuMScUVtYnMUCQe8dNEy9wlzHFlvVDImBvwrSt7PTUc5v0K3K9jYRAxfj7DemjGt3w3scvgKmv4Ub21wrdgmzNG01W01tqjEmz_LIBzed3yHaIk82ky3gjMc1LweqhVSI6zkU0lgkn74H_TOIST36g80l_jzRFUcHwM-xuEgjUQ7zqq2ugAJ4-IUxLYN_Snr-J37znxRippfRn0CseRkq_8BF7brcFDJykzIySaMrlIPKazpsEilbSQLrzuOZPmmFHrqKVY-LKphM2NLSQKVigtnPPSjDPpjM6yU6iOJ2M8A4KaBpJA52-lhhmWGqEKy4zjOZpcW3oOtbADo-mK_GJULv7i7-5b2O0MXrqj7lPv-RL2vHWhVoF7V1BdzJZ4DTv2e_Exn93Es_sB6smYGg
openUrl ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=proceeding&rft.title=2018+IEEE%2FACM+International+Conference+on+Computer-Aided+Design+%28ICCAD%29&rft.atitle=Watermarking+Deep+Neural+Networks+for+Embedded+Systems&rft.au=Guo%2C+Jia&rft.au=Potkonjak%2C+Miodrag&rft.date=2018-11-01&rft.pub=ACM&rft.eissn=1558-2434&rft.spage=1&rft.epage=8&rft_id=info:doi/10.1145%2F3240765.3240862&rft.externalDocID=8587745