Font Size: a A A

Research On Lossless Watermark And Integrity Authentication Of Deep Learning Model

Posted on:2023-07-17Degree:DoctorType:Dissertation
Country:ChinaCandidate:X Q GuanFull Text:PDF
GTID:1528306905964289Subject:Cyberspace security
Abstract/Summary:
With the popularity of Internet applications,in recent years,the amount of information is growing explosively.As a technology that can acquire knowledge and process information in massive data,deep learning is widely utilized in data mining,computer vision,natural language processing and other fields.As a means of deep learning technology,deep learning model has great application potential and commercial value,which leads to a series of security problems such as piracy and tampering.In order to deal with these potential attacks,model watermarking technology,an active protection measure,is applied for model copyright protection or integrity authentication by embedding special watermark information into the model.However,although the embedding of these watermark information has little impact on the performance of the model,it will permanently modify the parameters and destroy the integrity of the model,which cannot meet the needs of integrity authentication applications.In addition,the existing model watermarking methods are difficult to locate the tampered areas of the model,and cannot restore the tampered key parameters.Therefore,it has become an urgent need to design a lossless model watermark and construct an integrity authentication scheme including model tamper location and restoration.According to the mastery of the internal structure and parameters of the model,the current deep learning application is mainly divided into two scenarios:white-box model and black-box model.For the sake of realizing the integrity authentication scheme of deep learning model,two different lossless watermarks are proposed in this dissertation:for the white-box model whose internal information can be completely obtained,this dissertation proposes a reversible watermarking method to achieve the integrity authentication,tamper location and restoration by using the extracted watermark information;For the black-box model whose internal information cannot be obtained and can only be accessed remotely,this dissertation proposes a unmodified watermarking method without modifying the model parameters,so as to ensure that the user can authenticate the integrity of model only through the input and output data.In addition,in order to protect the model in the face of the tampering behavior of attackers and unreliable storage platforms,this dissertation combines two lossless watermarking methods and integrity authentication schemes to protect the data security of deep learning shared model.The main research contents and innovations of this dissertation include:1.Propose a reversible watermarking method of deep learning modelIn order to overcome the limitations of existing methods to permanently modify the model parameters,a white-box model reversible watermarking method is proposed in this dissertation by designing the parameter importance measurement standard,data processing strategy,constructing the watermark embedding carrier and applying the reversible information hiding technology,so that the users can completely reconstruct the model parameters while extracting the watermark information.In addition,this dissertation also contains two schemes to improve the reversible watermark of the white-box model.By improving the parameter importance measurement index and increasing the parameter blocking operation,the embedding capacity of the reversible watermark of the model is further improved and the impact of watermark embedding on the performance of the model is reduced.The experimental results show that the reversible watermark of the white-box model proposed in this dissertation is fragile,the m ethod is strictly reversible,and the embedding of the watermark has little impact on the performance of the model.After extracting the watermark information,the model user can completely reconstruct the model parameters and effectively preserve the integrity of the model.2.Propose an integrity authentication method of white-box model based on reversible watermarkBy combining the advantages of reversible watermark to preserve the integrity of the model,a white-box model integrity authentication method based on reversible watermark is proposed to realize the functions of white-box model tamper detection,tamper location and tamper restoration in this dissertation.In the whole integrity authentication,the model holder embeds the watermark information containing the whole characteristics of the model into parameters by using the reversible watermarking method.The user realizes the whole integrity authentication of the model by comparing the extracted watermark information with the characteristic information generated by the reconstructed model.In the local integrity authentication,the model holder blocks the model parameters,constructs a block mapping sequence,and then embeds the recovery watermark and authentication watermark into parameters,so that the user can locate the tampered areas and restore the tampered parameters through the extracted watermark information.In addition,combined with the different tampering strategies of attackers on model parameters under different restrictions,the restoration rate of tampering parameters in the real attack scenario is discussed in this dissertation.The experimental results show that these two kinds of integrity authentication methods can accurately detect the tampering of model parameters by attackers,and the local integrity authentication method can locate the tampered area absolutely and repair the tampered parameters effectively.3.Propose unmodified watermarking method and integrity authentication framework of black-box modelIn this dissertation,a black-box model unmodified watermarking method is proposed,which enables the user to realize the representation of watermark information without modifying and reconstructing the model parameters.During the design of this method,a set of input data close to the decision boundary of the model is constructed iteratively,and the output results is encoded by a specific coding algorithm to represent the unmodified watermark information.In addition,a black-box model integrity authentication method based on unmodified watermark is also proposed in this dissertation.When the model can only be accessed remotely through the interface,the user sends those special input data shared with the model holder into the model and extracts the watermark information to realize the integrity authentication.The experimental results show that the whole integrity authentication method of black-box model can detect the tampering behavior of attackers on the model effectively,and further expand the application scenario of model integrity authentication.4.Propose an integrity authentication method of model sharing scenarioBy combining reversible watermarking and unmodified watermarking methods,this dissertation designs integrity authentication strategies for the shared model in the case of remote access model and local download model respectively,so as to deal with the two attack behaviors of potential attackers tampering with model parameters and unreliable shared platform tampering with model parameters,provide early warning tips for platforms and reduce the risk of using the s hared model.The experimental results show that the integrity authentication scheme of the shared model can effectively detect the tampering behavior of attackers and protect the data security of the deep learning model at a low time cost.
Keywords/Search Tags:Deep learning model security, integrity authentication, lossless watermark, reversible watermark, unmodified watermark
Related items