Turn Passive to Active: A Survey on Active Intellectual Property Protection of Deep Learning Models

Mingfu Xue,Leo Yu Zhang,Yushu Zhang,Weiqiang Liu
2023-10-15
Abstract:The intellectual property protection of deep learning (DL) models has attracted increasing serious concerns. Many works on intellectual property protection for Deep Neural Networks (DNN) models have been proposed. The vast majority of existing work uses DNN watermarking to verify the ownership of the model after piracy occurs, which is referred to as passive verification. On the contrary, we focus on a new type of intellectual property protection method named active copyright protection, which refers to active authorization control and user identity management of the DNN model. As of now, there is relatively limited research in the field of active DNN copyright protection. In this review, we attempt to clearly elaborate on the connotation, attributes, and requirements of active DNN copyright protection, provide evaluation methods and metrics for active copyright protection, review and analyze existing work on active DL model intellectual property protection, discuss potential attacks that active DL model copyright protection techniques may face, and provide challenges and future directions for active DL model intellectual property protection. This review is helpful to systematically introduce the new field of active DNN copyright protection and provide reference and foundation for subsequent work.
Cryptography and Security,Computer Vision and Pattern Recognition
What problem does this paper attempt to address?
The problem this paper attempts to address is the intellectual property protection of deep learning models, specifically how to shift from passive verification to active authorization control to achieve intellectual property protection for deep neural network (DNN) models. Most existing work focuses on verifying model ownership by embedding watermarks in the model or extracting model signatures, which is known as passive verification. However, this approach cannot actively prevent piracy and infringement. Therefore, this review article focuses on a new method of intellectual property protection—active copyright protection, which refers to the active authorization control and user identity management of DNN models. The article aims to clearly articulate the connotation, attributes, and requirements of active DNN copyright protection, provide evaluation methods and metrics, review and analyze existing work, discuss potential attacks, and propose challenges and future research directions. Through these efforts, the article hopes to provide a reference and foundation for systematically introducing the new field of active DNN copyright protection, thereby promoting the development of subsequent research.