跳到主要导航 跳到搜索 跳到主要内容

PUF-Based Intellectual Property Protection for CNN Model

  • Beihang University
  • Ltd.

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

It usually takes a lot of time and resources to train a high-accurate Machine Learning model, so it is believed that the trainer owns the Intellectual Property (IP) of the model. With the help of various computing accelerators, a Machine Learning model can run on FPGAs, and model providers render services by selling FPGAs with models embedded. Unauthorized copying of the model infringes the owner’s copyrights, so there is an urgent need for the effective protection of model IP. In this paper, we propose a Physical Unclonable Function (PUF) based CNN model IP protection scheme. Before selling the model, the model providers confuse the parameters of the model with the response of a PUF, then embed the confused model into the FPGA where the PUF is. In this way, the protected model can get correct results only if running on the specific FPGA. Experimental results show that the performance difference between the confused model and the original model is negligible, and it is difficult for the adversary to get the correct parameters. Our approach effectively protects the IP of the model by restricting the model to only run on the specified FPGA and is easily extended to other models with convolutional layers and linear fully connected layers.

源语言英语
主期刊名Knowledge Science, Engineering and Management - 15th International Conference, KSEM 2022, Proceedings
编辑Gerard Memmi, Baijian Yang, Linghe Kong, Tianwei Zhang, Meikang Qiu
出版商Springer Science and Business Media Deutschland GmbH
722-733
页数12
ISBN(印刷版)9783031109881
DOI
出版状态已出版 - 2022
活动15th International Conference on Knowledge Science, Engineering and Management, KSEM 2022 - Singapore, 新加坡
期限: 6 8月 20228 8月 2022

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
13370 LNAI
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议15th International Conference on Knowledge Science, Engineering and Management, KSEM 2022
国家/地区新加坡
Singapore
时期6/08/228/08/22

指纹

探究 'PUF-Based Intellectual Property Protection for CNN Model' 的科研主题。它们共同构成独一无二的指纹。

引用此