Training CNN models necessitates substantial investments in training data and computational resources, making the models the intellectual property of the owners. Therefore, model watermarking technology is widely utilized in model copyright protection. Watermark detection relies on key input triggers, which are required to be kept private for security. However, this requirement complicates the ownership verification by third-party clients in model counterfeiting scenarios. To prevent counterfeiters from utilizing fake models as claimed models to deceive clients, we present CNNOVZKP, the first framework utilizing zero-knowledge proofs to address the model counterfeiting problem. CNNOVZKP allows an entity to validate whether the service provider owns the claimed model, while preserving the privacy of the watermarks. Then, we present CNNOVZKPv1, a variant of CNNOVZKP designed for CNNs with black-box watermarks. This version further reduces the chances of counterfeiters deceiving clients compared to CNNOVZKP. Both CNNOVZKP and CNNOVZKPv1 permit a third-party client to verify ownership proof within two seconds, requiring less 1 KB of communication. Our works provide a viable solution for neural network ownership verification in model counterfeiting scenarios.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

CNNOVZKP: Convolutional Neural Network Model Ownership Verification with Zero-Knowledge Proof

  • Yuhao Lian,
  • Ying Ouyang,
  • Songsong Li,
  • Deng Tang

摘要

Training CNN models necessitates substantial investments in training data and computational resources, making the models the intellectual property of the owners. Therefore, model watermarking technology is widely utilized in model copyright protection. Watermark detection relies on key input triggers, which are required to be kept private for security. However, this requirement complicates the ownership verification by third-party clients in model counterfeiting scenarios. To prevent counterfeiters from utilizing fake models as claimed models to deceive clients, we present CNNOVZKP, the first framework utilizing zero-knowledge proofs to address the model counterfeiting problem. CNNOVZKP allows an entity to validate whether the service provider owns the claimed model, while preserving the privacy of the watermarks. Then, we present CNNOVZKPv1, a variant of CNNOVZKP designed for CNNs with black-box watermarks. This version further reduces the chances of counterfeiters deceiving clients compared to CNNOVZKP. Both CNNOVZKP and CNNOVZKPv1 permit a third-party client to verify ownership proof within two seconds, requiring less 1 KB of communication. Our works provide a viable solution for neural network ownership verification in model counterfeiting scenarios.