Skip to main navigation Skip to search Skip to main content

PUF-Based Intellectual Property Protection for CNN Model

  • Beihang University
  • Ltd.

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

It usually takes a lot of time and resources to train a high-accurate Machine Learning model, so it is believed that the trainer owns the Intellectual Property (IP) of the model. With the help of various computing accelerators, a Machine Learning model can run on FPGAs, and model providers render services by selling FPGAs with models embedded. Unauthorized copying of the model infringes the owner’s copyrights, so there is an urgent need for the effective protection of model IP. In this paper, we propose a Physical Unclonable Function (PUF) based CNN model IP protection scheme. Before selling the model, the model providers confuse the parameters of the model with the response of a PUF, then embed the confused model into the FPGA where the PUF is. In this way, the protected model can get correct results only if running on the specific FPGA. Experimental results show that the performance difference between the confused model and the original model is negligible, and it is difficult for the adversary to get the correct parameters. Our approach effectively protects the IP of the model by restricting the model to only run on the specified FPGA and is easily extended to other models with convolutional layers and linear fully connected layers.

Original languageEnglish
Title of host publicationKnowledge Science, Engineering and Management - 15th International Conference, KSEM 2022, Proceedings
EditorsGerard Memmi, Baijian Yang, Linghe Kong, Tianwei Zhang, Meikang Qiu
PublisherSpringer Science and Business Media Deutschland GmbH
Pages722-733
Number of pages12
ISBN (Print)9783031109881
DOIs
StatePublished - 2022
Event15th International Conference on Knowledge Science, Engineering and Management, KSEM 2022 - Singapore, Singapore
Duration: 6 Aug 20228 Aug 2022

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13370 LNAI
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference15th International Conference on Knowledge Science, Engineering and Management, KSEM 2022
Country/TerritorySingapore
CitySingapore
Period6/08/228/08/22

Keywords

  • CNN
  • FPGA
  • IP protection
  • Machine learning
  • PUF

Fingerprint

Dive into the research topics of 'PUF-Based Intellectual Property Protection for CNN Model'. Together they form a unique fingerprint.

Cite this