A Protection Method of Trained CNN Model Using Feature Maps Transformed With Secret Key From Unauthorized Access
Autor: | AprilPyone, MaungMaung, Kiya, Hitoshi |
---|---|
Rok vydání: | 2021 |
Předmět: | |
Druh dokumentu: | Working Paper |
Popis: | In this paper, we propose a model protection method for convolutional neural networks (CNNs) with a secret key so that authorized users get a high classification accuracy, and unauthorized users get a low classification accuracy. The proposed method applies a block-wise transformation with a secret key to feature maps in the network. Conventional key-based model protection methods cannot maintain a high accuracy when a large key space is selected. In contrast, the proposed method not only maintains almost the same accuracy as non-protected accuracy, but also has a larger key space. Experiments were carried out on the CIFAR-10 dataset, and results show that the proposed model protection method outperformed the previous key-based model protection methods in terms of classification accuracy, key space, and robustness against key estimation attacks and fine-tuning attacks. Comment: To appear in APSIPA 2021. arXiv admin note: text overlap with arXiv:2105.14756 |
Databáze: | arXiv |
Externí odkaz: |