TY - JOUR
T1 - Protecting artificial intelligence IPs
T2 - a survey of watermarking and fingerprinting for machine learning
AU - Regazzoni, Francesco
AU - Palmieri, Paolo
AU - Smailbegovic, Fethulah
AU - Cammarota, Rosario
AU - Polian, Ilia
PY - 2021
Y1 - 2021
N2 - Artificial intelligence (AI) algorithms achieve outstanding results in many application domains such as computer vision and natural language processing. The performance of AI models is the outcome of complex and costly model architecture design and training processes. Hence, it is paramount for model owners to protect their AI models from piracy – model cloning, illegitimate distribution and use. IP protection mechanisms have been applied to AI models, and in particular to deep neural networks, to verify the model ownership. State-of-the-art AI model ownership protection techniques have been surveyed. The pros and cons of AI model ownership protection have been reported. The majority of previous works are focused on watermarking, while more advanced methods such fingerprinting and attestation are promising but not yet explored in depth. This study has been concluded by discussing possible research directions in the area.
AB - Artificial intelligence (AI) algorithms achieve outstanding results in many application domains such as computer vision and natural language processing. The performance of AI models is the outcome of complex and costly model architecture design and training processes. Hence, it is paramount for model owners to protect their AI models from piracy – model cloning, illegitimate distribution and use. IP protection mechanisms have been applied to AI models, and in particular to deep neural networks, to verify the model ownership. State-of-the-art AI model ownership protection techniques have been surveyed. The pros and cons of AI model ownership protection have been reported. The majority of previous works are focused on watermarking, while more advanced methods such fingerprinting and attestation are promising but not yet explored in depth. This study has been concluded by discussing possible research directions in the area.
UR - http://www.scopus.com/inward/record.url?scp=85103546968&partnerID=8YFLogxK
U2 - 10.1049/cit2.12029
DO - 10.1049/cit2.12029
M3 - Review article
AN - SCOPUS:85103546968
SN - 2468-6557
VL - 6
SP - 180
EP - 191
JO - CAAI Transactions on Intelligence Technology
JF - CAAI Transactions on Intelligence Technology
IS - 2
ER -