Powered by OpenAIRE graph
Found an issue? Give us feedback
addClaim

Machine Learning Model Watermarking through DRAM PUFs

Authors: Khatun, Arju;

Machine Learning Model Watermarking through DRAM PUFs

Abstract

In the modern day, neural networks are of utmost importance, and their applications can be found across a wide range of areas including social media, healthcare, navigation, and personal assistance. Modern neural networks are large-scale and contain billions of parameters. Hence, training these networks is a costly affair, both in terms of resources and finances. With the rising cost of training, security concerns over model theft have also emerged, where an adversarial party may replicate a pre-trained model without proper authorization and deploy it for their advantage. Watermarking serves as a tool that, in such scenarios, allows the legitimate owner to claim the authenticity of the stolen model. Researchers have developed various watermarking schemes for neural networks, typically by modifying the training code. In this thesis, I worked on developing a hardware-based watermarking scheme utilizing the PUF (Physical Unclonable Function) characteristics of DRAM modules. PUFs can work as strong hardware-based security fingerprints, and DRAMs have been shown to exhibit inherent PUF behavior. One way to generate a PUF from DRAM is by disabling the DRAM refresh mechanism, which causes bit-flips in the stored charge. In my work, a machine learning model is trained on a PUF-enabled DRAM platform where the model parameters are stored directly on the decaying DRAM cells. This process integrates the DRAM's PUF into the model parameters, and enables embedding of a robust watermark without making any modifications to the training code.

In the modern day, neural networks are crucial in many different areas of our lives, with applications found across fields such as social media, healthcare, navigation, and personal assistance. Before a neural network is ready to be used, it needs to be trained. Modern neural networks are large and require significant resources to train, making the training process costly. As training costs rise, there is growing concern over model theft, where someone could illegally copy a pre-trained model and use it as their own. In such scenarios, watermarks provide a way for the original owner to identify their models and claim copyright. The majority of current research on neural network watermarking requires changes to the training code. In this work, I developed a hardware-based watermarking method that uses a hardware feature called a Physical Unclonable Function (PUF). DRAM PUFs naturally occur in computer memory (DRAM) when refresh operations are turned off, causing small-scale random changes in the data. I built a system where a neural network is trained on such a memory platform, and the model's parameters are stored directly on the decaying memory. This embeds a hidden, unique signature into the model and serves as a watermark — without changing the training code.

Master of Science

Country
United States
Related Organizations
Keywords

DRAM, Watermark, Hardware Acceleration, Neural-Network, FPGA

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Upload OA version
Are you the author of this publication? Upload your Open Access version to Zenodo!
It’s fast and easy, just two clicks!