Dataless Black-Box Model Comparison

被引:0
|
作者
Theiss C. [1 ]
Brust C.A. [1 ]
Denzler J. [1 ]
机构
[1] Computer Vision Group, Friedrich Schiller University Jena, Jena
关键词
black-box; function space; model comparison;
D O I
10.1134/S1054661818040272
中图分类号
学科分类号
摘要
In a time where the training of new machine learning models is extremely time-consuming and resource-intensive and the sale of these models or the access to them is more popular than ever, it is important to think about ways to ensure the protection of these models against theft. In this paper, we present a method for estimating the similarity or distance between two black-box models. Our approach does not depend on the knowledge about specific training data and therefore may be used to identify copies of or stolen machine learning models. It can also be applied to detect instances of license violations regarding the use of datasets. We validate our proposed method empirically on the CIFAR-10 and MNIST datasets using convolutional neural networks, generative adversarial networks and support vector machines. We show that it can clearly distinguish between models trained on different datasets. Theoretical foundations of our work are also given. © 2018, Pleiades Publishing, Ltd.
引用
收藏
页码:676 / 683
页数:7
相关论文
共 50 条
  • [1] Dataless Black-Box Model Comparison
    Theiss, Christoph
    Brust, Clemens-Alexander
    Denzler, Joachim
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE (ICPRAI 2018), 2018, : 622 - 626
  • [2] A Black-box Model for Neurons
    Roqueiro, N.
    Claumann, C.
    Guillamon, A.
    Fossas, E.
    2019 IEEE 10TH LATIN AMERICAN SYMPOSIUM ON CIRCUITS & SYSTEMS (LASCAS), 2019, : 129 - 132
  • [3] Beyond the black-box model
    不详
    FOUNDATIONS AND TRENDS IN MACHINE LEARNING, 2015, 8 (3-4): : 309 - 328
  • [4] Black-box modeling of residential HVAC system and comparison of gray-box and black-box modeling methods
    Afram, Abdul
    Janabi-Sharifi, Farrokh
    ENERGY AND BUILDINGS, 2015, 94 : 121 - 149
  • [5] COMPARISON OF A BLACK-BOX MODEL TO A TRADITIONAL NUMERICAL MODEL FOR HYDRAULIC HEAD PREDICTION
    Tapoglou, E.
    Chatzakis, A.
    Karatzas, G. P.
    GLOBAL NEST JOURNAL, 2016, 18 (04): : 761 - 770
  • [6] A model for analyzing black-box optimization
    Phan, Vinhthuy
    Skiena, Steven
    Sumazin, Pavel
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2003, 2748 : 424 - 438
  • [7] A model for analyzing black-box optimization
    Phan, V
    Skiena, S
    Sumazin, P
    ALGORITHMS AND DATA STRUCTURES, PROCEEDINGS, 2003, 2748 : 424 - 438
  • [8] The black-box model for cryptographic primitives
    Schnorr, CP
    Vaudenay, S
    JOURNAL OF CRYPTOLOGY, 1998, 11 (02) : 125 - 140
  • [9] The Black-Box Model for Cryptographic Primitives
    Claus Peter Schnorr
    Serge Vaudenay
    Journal of Cryptology, 1998, 11 : 125 - 140
  • [10] Opening the Black-Box of Model Transformation
    Saxon, John T.
    Bordbar, Behzad
    Akehurst, David H.
    MODELLING FOUNDATIONS AND APPLICATIONS, 2015, 9153 : 171 - 186