Pith. sign in

REVIEW 1 cited by

Deep-Lock: Secure Authorization for Deep Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2008.05966 v2 pith:MWEPCMR7 submitted 2020-08-13 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords modelsdeep-lockmodeldeepnetworkneuralpropertiesscheme
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Trained Deep Neural Network (DNN) models are considered valuable Intellectual Properties (IP) in several business models. Prevention of IP theft and unauthorized usage of such DNN models has been raised as of significant concern by industry. In this paper, we address the problem of preventing unauthorized usage of DNN models by proposing a generic and lightweight key-based model-locking scheme, which ensures that a locked model functions correctly only upon applying the correct secret key. The proposed scheme, known as Deep-Lock, utilizes S-Boxes with good security properties to encrypt each parameter of a trained DNN model with secret keys generated from a master key via a key scheduling algorithm. The resulting dense network of encrypted weights is found robust against model fine-tuning attacks. Finally, Deep-Lock does not require any intervention in the structure and training of the DNN models, making it applicable for all existing software and hardware implementations of DNN.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Probe-Me-Not: Protecting Pre-trained Encoders from Malicious Probing

    cs.CR 2024-11 conditional novelty 6.0 of 10

    EncoderLock modifies a small set of pre-trained encoder weights so that linear probing succeeds on authorized domains while failing on prohibited domains, in supervised, unsupervised, and zero-shot data scenarios.

Pith tools