Perceptual Model Hashing: Towards Neural Network Model Authentication

Xinran Li,Zichi Wang,Guorui Feng,Xinpeng Zhang,Chuan Qin
DOI: https://doi.org/10.1109/mmsp55362.2022.9949087
2022-01-01
Abstract:A lot of excellent neural network models are valuable wealth to the field of artificial intelligence, which may be plagiarized and distributed without authorization. For this reason, few research establishments and industries reveal the internals of their neural network models. To authenticate suspicious pirated models, this letter proposes a gray-box hashing method for the neural network models that designed for image classification. In the proposed method, the hash sequence of original model can be extracted without knowing both the structure and weight parameters except the vectors in output layer. To the best of our knowledge, this is the first work focusing on gray-box perceptual model hashing to identify and authenticate neural network models. Experimental results show that our method performs satisfactory perceptual robustness and discrimination capability, and can effectively classify perceptual similar versions of the original model and distinct models.
What problem does this paper attempt to address?