{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:30:39Z","timestamp":1783611039651,"version":"3.55.0"},"reference-count":38,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2022,4,28]],"date-time":"2022-04-28T00:00:00Z","timestamp":1651104000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Department of Science and Technology, Government of India"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["J. Emerg. Technol. Comput. Syst."],"published-print":{"date-parts":[[2022,7,31]]},"abstract":"<jats:p>\n            The prevalent usage and unparalleled recent success of Deep Neural Network (DNN) applications have raised the concern of protecting their Intellectual Property (IP) rights in different business models to prevent the theft of trade secrets. In this article, we propose a lightweight, generic, key-based DNN IP protection methodology,\n            <jats:italic>NN-Lock<\/jats:italic>\n            , to defend against unauthorized usage of stolen DNN models.\n            <jats:italic>NN-Lock<\/jats:italic>\n            utilizes SBox, a cryptographic primitive, with good security properties to encrypt each parameter of a trained DNN model with the secret keys derived from a master key through a key-scheduling algorithm. The method ensures that only an authorized user with a correct master key can accurately use the locked DNN model. Evaluation results of\n            <jats:italic>NN-Lock<\/jats:italic>\n            on a Google Coral edge device for various DNN architectures on several datasets show that for an incorrect master key, the accuracy of a locked model is that of a random classifier. The dense network of encrypted parameters makes the method robust against the\n            <jats:italic>model fine-tuning attack<\/jats:italic>\n            and a novel\n            <jats:italic>approximation attack<\/jats:italic>\n            using the Genetic Algorithm, which achieves reasonable success against another recent IP protection scheme called HPNN\u00a0Chakraborty et\u00a0al.\n            <jats:xref ref-type=\"bibr\">2020<\/jats:xref>\n            . The security evaluation of\n            <jats:italic>NN-Lock<\/jats:italic>\n            against other families of attacks demonstrates its soundness in practical scenarios.\n            <jats:italic>NN-Lock<\/jats:italic>\n            does not modify any internal structure of a DNN model, making it scalable for all of the existing DNN implementations without adversely affecting their performance.\n          <\/jats:p>","DOI":"10.1145\/3505634","type":"journal-article","created":{"date-parts":[[2022,2,2]],"date-time":"2022-02-02T22:15:29Z","timestamp":1643840129000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["<i>NN-Lock<\/i>\n            : A Lightweight Authorization to Prevent IP Threats of Deep Learning Models"],"prefix":"10.1145","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3338-2944","authenticated-orcid":false,"given":"Manaar","family":"Alam","sequence":"first","affiliation":[{"name":"Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sayandeep","family":"Saha","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Debdeep","family":"Mukhopadhyay","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sandip","family":"Kundu","sequence":"additional","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,4,28]]},"reference":[{"key":"e_1_3_2_2_1","first-page":"265","volume-title":"12th USENIX Symposium on Operating Systems Design and Implementation (OSDI\u201916), Savannah, GA, November 2\u20134, 2016","author":"Abadi Mart\u00edn","year":"2016","unstructured":"Mart\u00edn Abadi et\u00a0al. 2016. TensorFlow: A system for large-scale machine learning. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI\u201916), Savannah, GA, November 2\u20134, 2016. USENIX Association, 265\u2013283. https:\/\/www.usenix.org\/conference\/osdi16\/technical-sessions\/presentation\/abadi."},{"key":"e_1_3_2_3_1","first-page":"1615","volume-title":"27th USENIX Security Symposium (USENIX Security\u201918), Baltimore, MD, August 15\u201317, 2018","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi, Carsten Baum, Moustapha Ciss\u00e9, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX Security Symposium (USENIX Security\u201918), Baltimore, MD, August 15\u201317, 2018. USENIX Association, 1615\u20131631. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/adi."},{"key":"e_1_3_2_4_1","volume-title":"Machine Learning on AWS","author":"Inc. Amazon Web Services,","year":"2020","unstructured":"Amazon Web Services, Inc.2020. Machine Learning on AWS. Retrieved February 22, 2022 from https:\/\/aws.amazon.com\/machine-learning\/."},{"key":"e_1_3_2_5_1","doi-asserted-by":"publisher","DOI":"10.13154\/tches.v2019.i1.97-122"},{"key":"e_1_3_2_6_1","first-page":"515","volume-title":"28th USENIX Security Symposium (USENIX Security\u201919), Santa Clara, CA, August 14\u201316, 2019","author":"Batina Lejla","year":"2019","unstructured":"Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. CSI NN: Reverse engineering of neural network architectures through electromagnetic side channel. In 28th USENIX Security Symposium (USENIX Security\u201919), Santa Clara, CA, August 14\u201316, 2019, Nadia Heninger and Patrick Traynor (Eds.). USENIX Association, 515\u2013532. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/batina."},{"key":"e_1_3_2_7_1","volume-title":"R","author":"Inc. BigML,","year":"2020","unstructured":"BigML, Inc.2020. Retrieved February 22, 2022 from BigML. https:\/\/bigml.com\/."},{"key":"e_1_3_2_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-06734-6_17"},{"key":"e_1_3_2_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-68914-0_27"},{"key":"e_1_3_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218651"},{"key":"e_1_3_2_11_1","article-title":"AES proposal: Rijndael","author":"Daemen Joan","year":"1999","unstructured":"Joan Daemen and Vincent Rijmen. 1999. AES proposal: Rijndael. NIST (1999). Retrieved February 22, 2022 from https:\/\/csrc.nist.gov\/csrc\/media\/projects\/cryptographic-standards-and-guidelines\/documents\/aes-development\/rijndael-ammended.pdf.","journal-title":"NIST"},{"key":"e_1_3_2_12_1","article-title":"MaskedNet: A pathway for secure inference against power side-channel attacks","volume":"1910","author":"Dubey Anuj","year":"2019","unstructured":"Anuj Dubey, Rosario Cammarota, and Aydin Aysu. 2019. MaskedNet: A pathway for secure inference against power side-channel attacks. CoRR abs\/1910.13063 (2019). arxiv:1910.13063http:\/\/arxiv.org\/abs\/1910.13063.","journal-title":"CoRR"},{"key":"e_1_3_2_13_1","volume-title":"Using a Trusted Platform Module for endpoint device security in AWS IoT Greengrass","author":"Ganapathy Krishnan","year":"2019","unstructured":"Krishnan Ganapathy. 2019. Using a Trusted Platform Module for endpoint device security in AWS IoT Greengrass. Retrieved February 22, 2022 from https:\/\/aws.amazon.com\/blogs\/iot\/using-a-trusted-platform-module-for-endpoint-device-security-in-aws-iot-greengrass\/."},{"key":"e_1_3_2_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/534133"},{"key":"e_1_3_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/JETCAS.2021.3076151"},{"key":"e_1_3_2_16_1","volume-title":"Coral - Build beneficial and privacy preserving AI","author":"LLC. Google","year":"2020","unstructured":"Google LLC.2020a. Coral - Build beneficial and privacy preserving AI. Retrieved February 22, 2022 from https:\/\/coral.ai\/."},{"key":"e_1_3_2_17_1","volume-title":"Dev Board datasheet","author":"LLC. Google","year":"2020","unstructured":"Google LLC.2020b. Dev Board datasheet. Retrieved February 22, 2022 from https:\/\/coral.ai\/docs\/dev-board\/datasheet\/."},{"key":"e_1_3_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240862"},{"key":"e_1_3_2_19_1","article-title":"Have you stolen my model? Evasion attacks against deep neural network watermarking techniques","volume":"1809","author":"Hitaj Dorjan","year":"2018","unstructured":"Dorjan Hitaj and Luigi V. Mancini. 2018. Have you stolen my model? Evasion attacks against deep neural network watermarking techniques. CoRR abs\/1809.00615 (2018). arXiv:1809.00615http:\/\/arxiv.org\/abs\/1809.00615.","journal-title":"CoRR"},{"key":"e_1_3_2_20_1","volume-title":"Intel Neural Compute Stick 2","author":"Corporation Intel","year":"2020","unstructured":"Intel Corporation. 2020. Intel Neural Compute Stick 2. Retrieved February 22, 2022 from https:\/\/software.intel.com\/en-us\/neural-compute-stick."},{"key":"e_1_3_2_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_22_1","volume-title":"The Hacks Behind Cracking, Part 1: How to Bypass Software Registration","author":"Long Alex","year":"2012","unstructured":"Alex Long. 2012. The Hacks Behind Cracking, Part 1: How to Bypass Software Registration. Retrieved February 22, 2022 from https:\/\/null-byte.wonderhowto.com\/how-to\/hacks-behind-cracking-part-1-bypass-software-registration-0132568\/."},{"key":"e_1_3_2_23_1","volume-title":"Self-driving car company Waymo raises $2.25 billion in first external round of funding","author":"McFarland Matt","year":"2020","unstructured":"Matt McFarland. 2020. Self-driving car company Waymo raises $2.25 billion in first external round of funding. Retrieved February 22, 2022 from https:\/\/www.click2houston.com\/news\/national\/2020\/03\/03\/self-driving-car-company-waymo-raises-225-billion-in-first-external-round-of-funding\/."},{"key":"e_1_3_2_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"key":"e_1_3_2_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_26_1","volume-title":"TPM 2.0: Securing IoT Deployments at the Edge","author":"Inc. Premio","year":"2020","unstructured":"Premio Inc.2020. TPM 2.0: Securing IoT Deployments at the Edge. Retrieved February 22, 2022 from https:\/\/premioinc.com\/blogs\/blog\/tpm-2-0-securing-iot-deployments-at-the-edge."},{"key":"e_1_3_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"e_1_3_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218600"},{"key":"e_1_3_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2015.7140252"},{"key":"e_1_3_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_2_31_1","article-title":"MimosaNet: An unrobust neural network preventing model stealing","volume":"1907","author":"Szentannai K\u00e1lm\u00e1n","year":"2019","unstructured":"K\u00e1lm\u00e1n Szentannai, Jalal Al-Afandi, and Andr\u00e1s Horv\u00e1th. 2019. MimosaNet: An unrobust neural network preventing model stealing. CoRR abs\/1907.01650 (2019). arXiv:1907.01650http:\/\/arxiv.org\/abs\/1907.01650.","journal-title":"CoRR"},{"key":"e_1_3_2_32_1","volume-title":"Post-training quantization","year":"2020","unstructured":"TensorFlow. 2020. Post-training quantization. Retrieved February 22, 2022 from https:\/\/www.tensorflow.org\/lite\/performance\/post_training_quantization."},{"key":"e_1_3_2_33_1","first-page":"601","volume-title":"25th USENIX Security Symposium (USENIX Security\u201916), Austin, TX, August 10\u201312, 2016","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction APIs. In 25th USENIX Security Symposium (USENIX Security\u201916), Austin, TX, August 10\u201312, 2016. USENIX Association, 601\u2013618. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/tramer."},{"key":"e_1_3_2_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-5906-5_511"},{"key":"e_1_3_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274696"},{"key":"e_1_3_2_36_1","article-title":"DeepObfuscation: Securing the structure of convolutional neural networks via knowledge distillation","volume":"1806","author":"Xu Hui","year":"2018","unstructured":"Hui Xu, Yuxin Su, Zirui Zhao, Yangfan Zhou, Michael R. Lyu, and Irwin King. 2018. DeepObfuscation: Securing the structure of convolutional neural networks via knowledge distillation. CoRR abs\/1806.10313 (2018). arxiv:1806.10313http:\/\/arxiv.org\/abs\/1806.10313.","journal-title":"CoRR"},{"key":"e_1_3_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133985"},{"key":"e_1_3_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300274"},{"key":"e_1_3_2_39_1","volume-title":"27th Annual Network and Distributed System Security Symposium (NDSS\u201920), San Diego, CA, February 23\u201326, 2020","author":"Yu Honggang","year":"2020","unstructured":"Honggang Yu, Kaichen Yang, Teng Zhang, Yun-Yun Tsai, Tsung-Yi Ho, and Yier Jin. 2020b. CloudLeak: Large-scale deep learning models stealing through adversarial examples. In 27th Annual Network and Distributed System Security Symposium (NDSS\u201920), San Diego, CA, February 23\u201326, 2020. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss-paper\/cloudleak-large-scale-deep-learning-models-stealing-through-adversarial-examples\/."}],"container-title":["ACM Journal on Emerging Technologies in Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3505634","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3505634","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:24Z","timestamp":1750182564000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3505634"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,28]]},"references-count":38,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,7,31]]}},"alternative-id":["10.1145\/3505634"],"URL":"https:\/\/doi.org\/10.1145\/3505634","relation":{},"ISSN":["1550-4832","1550-4840"],"issn-type":[{"value":"1550-4832","type":"print"},{"value":"1550-4840","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,4,28]]},"assertion":[{"value":"2021-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-04-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}