Deep Intellectual Property Protection: A Survey
Yuchen Sun, Tianpeng Liu, Panhe Hu, Qing Liao, Shaojing Fu, Nenghai, Yu, Deke Guo, Yongxiang Liu, Li Liu

TL;DR
This survey comprehensively reviews deep neural network intellectual property protection methods, focusing on deep watermarking and fingerprinting, analyzing over 190 contributions to identify challenges, metrics, and future directions.
Contribution
It provides the first extensive taxonomy and analysis of DNN IP protection techniques, summarizing recent research and proposing future research directions.
Findings
Deep watermarking and fingerprinting are the main IP protection methods.
Over 190 research contributions are analyzed in the survey.
The survey highlights challenges and promising future research directions.
Abstract
Deep Neural Networks (DNNs), from AlexNet to ResNet to ChatGPT, have made revolutionary progress in recent years, and are widely used in various fields. The high performance of DNNs requires a huge amount of high-quality data, expensive computing hardware, and excellent DNN architectures that are costly to obtain. Therefore, trained DNNs are becoming valuable assets and must be considered the Intellectual Property (IP) of the legitimate owner who created them, in order to protect trained DNN models from illegal reproduction, stealing, redistribution, or abuse. Although being a new emerging and interdisciplinary field, numerous DNN model IP protection methods have been proposed. Given this period of rapid evolution, the goal of this paper is to provide a comprehensive survey of two mainstream DNN IP protection methods: deep watermarking and deep fingerprinting, with a proposed taxonomy.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdversarial Robustness in Machine Learning · Biometric Identification and Security · Digital Media Forensic Detection
Methods*Communicated@Fast*How Do I Communicate to Expedia? · Average Pooling · 1x1 Convolution · Residual Connection · Global Average Pooling · Bottleneck Residual Block · Batch Normalization · Max Pooling · Kaiming Initialization · Convolution
