A Deep Model Intellectual Property Protection Method Supporting Public Verification
Abstract
Recently, the intellectual property protection methods based on deep learning have achieved great success, but there are still serious infringement issues that the network topology or hyper parameters of the trained model are stolen by third parties. In this paper, we construct a deep learning model based on the autoencoder to remove the bone from the medical images containing chest x-ray, and the specific trigger set is trained and predicted to get the effect of the backdoor watermark. The scheme of zero-knowledge proof is applied to transform the backdoor watermark of the model into the fixed-length string, which is published in the block chain to verify the ownership of the model. Through the non-interactive verification between the model owner and the third party, the ownership of the model can be confirmed by the third party and the verification process will not disclose any information of the model itself. The method proposed in this paper can support infinite times of verification and does not reveal any information about the model, so as to achieve the protection of intellectual property rights of the model.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.