You are caught stealing my winning lottery ticket! Making a lottery ticket claim its ownership
Despite tremendous success in many application scenarios, the training and\ninference costs of using deep learning are also rapidly increasing over time.\nThe lottery ticket hypothesis (LTH) emerges as a promising framework to\nleverage a special sparse subnetwork (i.e., winning ticket) instead of a full\nmodel for both training and inference, that can lower both costs without\nsacrificing the performance. The main resource bottleneck of LTH is however the\nextraordinary cost to find the sparse mask of the winning ticket. That makes\nthe found winning ticket become a valuable asset to the owners, highlighting\nthe necessity of protecting its copyright. Our setting adds a new dimension to\nthe recently soaring interest in protecting against the intellectual property\n(IP) infringement of deep models and verifying their ownerships, since they\ntake owners' massive/unique resources to develop or train. While existing\nmethods explored encrypted weights or predictions, we investigate a unique way\nto leverage sparse topological information to perform lottery verification, by\ndeveloping several graph-based signatures that can be embedded as credentials.\nBy further combining trigger set-based methods, our proposal can work in both\nwhite-box and black-box verification scenarios. Through extensive experiments,\nwe demonstrate the effectiveness of lottery verification in diverse models\n(ResNet-20, ResNet-18, ResNet-50) on CIFAR-10 and CIFAR-100. Specifically, our\nverification is shown to be robust to removal attacks such as model fine-tuning\nand pruning, as well as several ambiguity attacks. Our codes are available at\nhttps://github.com/VITA-Group/NO-stealing-LTH.\n
Paper
References (54)
Scroll for more · 38 remaining