用硬件唯一特性绑定神经网络模型,防止盗版复制。
A PUF-Based Approach for Copy Protection of Intellectual Property in Neural Network Models
- 利用物理不可克隆函数(PUF)将模型权重与硬件绑定。
- 在非目标硬件上运行时模型准确率显著下降。
- 适合保护高价值神经网络知识产权的企业使用。
越来越多公司的知识产权被嵌入神经网络(NN)模型中,这些模型具有重要价值,需有效保护。例如,攻击者可能复制生产硬件,并将原软件及神经网络模型移植到克隆设备上。为阻止此类行为,本文提出一种将神经网络模型及其内部知识产权绑定至底层硬件的方法。通过利用物理不可克隆函数(PUF),将模型权重与硬件的独特、不可复制属性关联。只有在原始目标硬件上才能恢复原始权重并实现足够精度,而在克隆硬件上则无法正常运行。我们在多种神经网络模型上验证了该方法的有效性,实现了预期的性能降级,并讨论了未来改进方向。
原文摘要 · Abstract (English)
More and more companies' Intellectual Property (IP) is being integrated into Neural Network (NN) models. This IP has considerable value for companies and, therefore, requires adequate protection. For example, an attacker might replicate a production machines' hardware and subsequently simply copy associated software and NN models onto the cloned hardware. To make copying NN models onto cloned hardware infeasible, we present an approach to bind NN models - and thus also the IP contained within them - to their underlying hardware. For this purpose, we link an NN model's weights, which are crucial for its operation, to unique and unclonable hardware properties by leveraging Physically Unclonable Functions (PUFs). By doing so, sufficient accuracy can only be achieved using the target hardware to restore the original weights, rendering proper execution of the NN model on cloned hardware impossible. We demonstrate that our approach accomplishes the desired degradation of accuracy on various NN models and outline possible future improvements.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。