A Protection against the Extraction of Neural Network Models
Chabanne, Hervé, Despiegel, Vincent, Guiga, Linda
Given oracle access to a Neural Network (NN), it is possible to extract its underlying model. We here introduce a protection by adding parasitic layers which keep the underlying NN's predictions mostly unchanged while complexifying the task of reverse-engineering. Our countermeasure relies on approximating a noisy identity mapping with a Convolutional NN. We explain why the introduction of new parasitic layers complexifies the attacks. We report experiments regarding the performance and the accuracy of the protected NN.
Jul-31-2020
- Country:
- North America
- United States > California
- San Diego County > San Diego (0.04)
- Los Angeles County > Long Beach (0.04)
- Canada > British Columbia
- United States > California
- Europe > Germany
- Saarland > Saarbrücken (0.04)
- North America
- Genre:
- Research Report (0.83)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: