The application belongs to the technical field of
artificial intelligence security and model
intellectual property protection, and discloses an
active defense and
access control method for a
deep learning model, which comprises the following steps: S1, generating a scalar
license sequence based on a private key parameter, and dividing a training round into
multiple stages, so that the stage indexes are consistent and the
license values corresponding to the indexes in the
license sequence are read; S2, constructing an authorized channel set in combination with channel static importance evaluation and channel chaos
score, generating an authorized
mask and an unauthorized
mask; S3, respectively calculating authorized task loss and unauthorized
confusion loss and jointly optimizing, and simultaneously implementing reset and gradient freezing on the parameters corresponding to the authorized channel set at the beginning of the training stage; S4, during model deployment and reasoning, the authorized end reconstructs the license sequence according to the shared key and generates the authorized
mask for reasoning, and the unauthorized end outputs performance degradation. The application improves the robustness to adaptive attacks and maintains the performance gap between authorized and unauthorized.