Depth model security deployment method and system based on softdog and watermark
By combining the generation of fragile watermarks and dongles, the problems of insufficient intellectual property protection and difficulty in tampering detection during the in-depth model deployment process are solved, and the legitimacy and integrity verification of the model is achieved, ensuring the security and correctness of the model deployment.
Patent Information
- Application Number
- CN202510452896.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-11
AI Technical Summary
The existing deep model protection methods have problems such as insufficient protection of model intellectual property rights, difficulty in tampering detection, high deployment cost and insufficient security during the model deployment process, especially the robustness of watermarks and the lack of reliability of verification mechanisms.
The deep model security deployment method based on dongle and watermark is adopted to ensure the legitimacy and integrity of the model by generating fragile watermarks, authorization encryption algorithms and dongle authorization decryption verification. The specific steps include building a 1*1 convolutional bypass layer to extract sensitive weights, calculating the sensitive weight score using an approximate Hessian matrix, generating a fragile watermark and encrypting and uploading; encrypting the model weights using an orthogonal matrix, and verifying legitimacy and integrity through dongles.
The authorization verification of the model, integrity verification and legality verification of the dongle are realized, ensuring the correctness and legality of model deployment, improving the accuracy and concealment of tamper detection, preventing unauthorized illegal access, and enhancing the security of the model deployment environment.
Smart Images

Figure CN120296706A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to a method and system for secure deployment of a deep model based on a dongle and watermarking. Background Art
[0002] With the rapid development of deep learning technology, deep neural networks (DNNs) have been widely applied in multiple fields such as computer vision, natural language processing, and autonomous driving. However, the training of deep models usually requires a large amount of computing resources and data, resulting in the models themselves having extremely high commercial value. Therefore, in the process of model deployment, how to protect the intellectual property rights of the models, prevent unauthorized use, prevent the models from being tampered with and causing errors, and ensure the integrity and security of the models has become an urgent problem to be solved.
[0003] Currently, common model protection methods include model encryption, access control, and trusted execution environment (TEE), etc. However, these methods still have certain limitations in practical applications. For example, traditional software encryption technology is easily cracked, the access control mechanism cannot effectively prevent model theft, and although the TEE technology can provide relatively high security, its deployment cost is high and it depends on a specific hardware environment, which limits the scope of application.
[0004] In recent years, the deep model protection technology based on watermarking has gradually attracted attention. This technology embeds verifiable information in the model weights, so that the legitimacy of the model can be guaranteed during the use and verification process. However, the existing watermarking methods still face some challenges, such as the robustness problem of the watermark, that is, it may fail after model fine-tuning, pruning, or quantization. In addition, the storage and verification of the watermark lack a reliable security mechanism, and attackers may avoid tracking by tampering with or removing the watermark, thus affecting the protection effect of the model. Summary of the Invention
[0005] Object of the Invention: The object of the present invention is to provide a method and system for secure deployment of a deep model based on a dongle and watermarking.
[0006] Technical Solution: The method for secure deployment of a deep model based on a dongle and watermarking according to the present invention includes the following steps:
[0007] Step 1: Generate a fragile watermark;
[0008] Step 2: Authorize the encryption algorithm;
[0009] Step 3: Dongle authorization decryption verification.
[0010] Further, the said Step 1 includes:
[0011] Step 11: Construct a bypass layer of 1*1 convolution according to the model, and initialize the weights W of the bypass layer bypass ;
[0012] Step 12: Read the model weights W;
[0013] Step 13: Sort W according to the absolute value of the gradient, select the top 30% with the largest gradient values as the initial weights, and use W l to represent the weight of the l-th layer among the selected weights, and use G l to represent the gradient corresponding to the l-th layer;
[0014] Step 14: Calculate the maximum eigenvalue λ of W using the approximate Hessian matrix method i ; max ;
[0015] Step 15: Calculate the final score S of the sensitivity weights of each layer according to formula (1.1) l :
[0016] S l = λ max · G l (1.1)
[0017] Step 16: Select the top 10% of the weights in S l as the final sensitivity weights of this layer, where
[0018] Step 17: The bypass layer in the model does not participate in training, that is the bypass layer is calculated according to formula (1.2):
[0019] O bypass = X * W bypass = 0 (1.2)
[0020] where * represents the convolution operation, and O bypass represents the output of this bypass layer.
[0021] Furthermore, after the model iterative training is completed, use formula (1.3) to extract the sensitivity weights of each layer stored in the bypass layer represents the gradient matrix of this layer; use formula (1.4) to standardize the weights, combine the model watermarks of each layer through formula (1.5) to form a fragile watermark, and finally encrypt the fragile watermark using SHA-256 and upload it to the cloud:
[0022]
[0023] where μ l represents the mean of the sensitivity weights of the l-th layer, σ l represents the standard deviation of the sensitivity weights of the l-th layer, and Wfragile Represents the final fragile watermark.
[0024] Further, the step 2 includes:
[0025] Step 21: Obtain the trained complete model weights W final of the intermediate layer W center , W final is generated by formula (2.1), W center is obtained using formula (2.2):
[0026] W final ={W main , W bypass} (2.1)
[0027]
[0028] where W main is the weight of the main task;
[0029] Step 22: Generate a random matrix A∈R center with the same dimension as W m×n , whose elements satisfy the standard normal distribution of independent and identically distributed:
[0030]
[0031] Step 23: Perform QR decomposition on the generated matrix A according to formula (2.4):
[0032]
[0033] where step (1) generates the orthogonal matrix Q w , step (3) verifies whether the generated orthogonal matrix meets the requirements, and I n represents the identity matrix.
[0034] Further, the intermediate layer W center applies the encryption transformation of the orthogonal matrix QW, and the specific form is:
[0035] W encrypted =Q W ×W center (2.5)
[0036] The weights after the intermediate layer change are called W encrypted , and use the encryption algorithm to encrypt W encrypted , and upload to the cloud, and at the same time store the corresponding private key S of AES in the private storage space of the encryption dog.
[0037] Further, the hardware ID of the dongle is bound to the fragile watermark to generate a unique UUID, which is implemented using the ECDSA signature algorithm. Then, the corresponding verification private key K is stored in the private storage area of the dongle. During verification, the signature must be verified first to ensure the legitimacy of the dongle, and then further authorization can be carried out.
[0038] Further, the encryption algorithm includes the AES encryption algorithm and the ChaCha20 encryption algorithm.
[0039] Further, the step 3 includes:
[0040] Step 31: The dongle uses the signature and UUID stored in its private storage area to download the public key K in the cloud through a secure communication channel for verification;
[0041] Step 32: After the dongle is verified as legitimate, obtain the encrypted model weights W from the customer encrypted , and obtain the transformation matrix in the cloud and give it to the dongle; the dongle decrypts the encrypted model weights using its private key S and restores them to the preliminarily decrypted weights W encrypted ;
[0042] Step 33: The dongle restores the decrypted model weights W encrypted to the original weights W through formula (3.1) final :
[0043]
[0044] Through this restoration process, the dongle will obtain the final weights that can be used for model inference and training.
[0045] Step 34: After the model weights are restored, extract the saved fragile watermark from the model bypass layer; the fragile watermark is encrypted and uploaded to the cloud for comparison;
[0046] Step 35: The dongle deploys the tamper-proof verified model to the corresponding physical device.
[0047] Further, in step 31, the legitimacy of the dongle is verified according to its UUID and signature. If the dongle passes the verification, the system allows the subsequent authorization process to continue; if the verification fails, the cloud will immediately send a warning to the model owner, indicating that the model is being illegally authorized, and abort the subsequent authorization process.
[0048] Further, in step 34, the fragile watermark is encrypted and uploaded to the cloud for comparison. If the two are consistent, the model verification is successful, indicating that the model has not been tampered with; if the comparison fails, the cloud will issue a warning, prompting the model owner that the model may have been tampered with and may cause adverse consequences.
[0049] The secure deployment system for deep models based on dongles and watermarks according to the present invention includes three core modules: a fragile watermark generation module, an authorization encryption module, and a dongle authorization decryption verification module, which are used to implement the authorization verification of the model, the integrity verification, and the legality verification of the dongle;
[0050] The fragile watermark generation module extracts sensitive weights from the model by constructing a 1*1 convolutional bypass layer, scores them, and selects the top 10% with the highest scores as fragile watermarks, which are stored in the bypass layer and encrypted and uploaded to the cloud;
[0051] The authorization encryption module selects the middle layer of the trained model, performs matrix operations using the generated orthogonal matrix A, shuffles the original weights and then encrypts them. The encrypted weights are uploaded to the cloud, and the key is stored in the private storage area of the dongle;
[0052] The dongle authorization decryption verification module, after obtaining the authorization qualification in the cloud, decrypts the model weights using the stored key and extracts the fragile watermark during the model deployment process; after successful verification, it indicates that the model has not been tampered with, and then the successfully verified model is used for deployment.
[0053] Advantages: Compared with the prior art, the present invention has the following remarkable advantages:
[0054] (1) Comprehensively ensure the secure deployment of AI models. Three core modules, namely a fragile watermark generation module, an authorization encryption module, and a dongle authorization decryption verification module, are designed to implement the authorization verification of the model, the integrity verification, and the legality verification of the dongle, ensuring the correctness and legality of model deployment;
[0055] (2) The fragile watermark is stored in the bypass layer, which is used to detect whether the model has been tampered with, and the output of the bypass layer is set to zero, thus not affecting the performance of model training, while significantly improving the accuracy and concealment of tampering detection;
[0056] (3) Through the authorization encryption module, the model weights are encrypted using the mathematical properties of the orthogonal matrix to achieve precise authorization control and prevent unauthorized illegal access;
[0057] (4) Adopt a multiple encryption mechanism, combined with the hardware characteristics of the dongle, and cooperate with software algorithms to ensure that both model deployers and end customers must complete model deployment through the dongle under the correct authorization conditions;
[0058] (5) Through a security protection system combining software and hardware, the security of the model deployment environment is further strengthened, effectively preventing the model from being cracked or illegally called. Description of the Drawings
[0059] Figure 1 is the flowchart of the present invention;
[0060] Figure 2 is the flowchart for generating fragile watermark;
[0061] Figure 3 is the flowchart for authorized encryption;
[0062] Figure 4 is the flowchart for dongle encryption;
[0063] Figure 5 is the flowchart for dongle decryption and authorization;
[0064] Figure 6 is the schematic diagram of the basic CNN model structure;
[0065] Figure 7 is the example output of the fragile watermark through SHA-256;
[0066] Figure 8 is the schematic diagram of weight matrix transformation;
[0067] Figure 9 is the schematic diagram of the dongle;
[0068] Figure 10 is the deployment result diagram;
[0069] Figure 11 is the schematic diagram of gradient sorting;
[0070] Figure 12 is the partial ciphertext of the authorized matrix after AES encryption. Detailed implementation manners
[0071] The technical solution of the present invention will be further described below with reference to the accompanying drawings.
[0072] As Figure 1 shown, the method for secure deployment of a deep model based on a dongle and a watermark according to the present invention includes the following steps:
[0073] Step 1: Generate a fragile watermark, and the flowchart is as Figure 2 shown;
[0074] Step 11: Construct a bypass layer of 1*1 convolution according to the model, and initialize the weight W bypass of the bypass layer;
[0075] Step 12: Read the model weight W;
[0076] Step 13: Sort W according to the absolute value of the gradient, select the top 30% of the gradient values as the initial weights, and use W l to represent the weight of the l-th layer in the selected weights, and use Gl represents the gradient corresponding to the l-th layer;
[0077] Step 14: Calculate W using the approximate Hessian matrix method i the maximum eigenvalue λ max ;
[0078] Step 15: Calculate the final score S of the sensitivity weight for each layer according to formula (1.1) l :
[0079] S l = λ max ·G l (1.1)
[0080] Step 16: Select the top 10% of the weights in S l as the final sensitivity weight for this layer
[0081] Step 17: The bypass layer in the model does not participate in training, that is the bypass layer is calculated according to formula (1.2):
[0082] O bypass = X * W bypass = 0 (1.2)
[0083] where * represents the convolution operation, and O bypass represents the output of this bypass layer.
[0084] Step 18: After the model is iteratively trained, use formula (1.3) to extract the sensitivity weights of each layer stored in the bypass layer represents the gradient matrix of this layer; use formula (1.4) to standardize the weights, combine the model watermarks of each layer through formula (1.5) to form a fragile watermark, and finally encrypt the fragile watermark using SHA-256 and upload it to the cloud:
[0085]
[0086] where μ l represents the mean of the sensitivity weights of the l-th layer, σ l represents the standard deviation of the sensitivity weights of the l-th layer, and W fragile represents the final fragile watermark.
[0087] Step 2: Authorize the encryption algorithm, and the flowchart is as Figure 3 shown;
[0088] Step 21: Obtain the intermediate layer W final of the trained complete model weight W center , W final is generated by formula (2.1), Wcenter Obtained using formula (2.2):
[0089] W final ={W main , W bypass}(2.1)
[0090]
[0091] where W main is the weight of the main task;
[0092] Step 22: Generate a random matrix A ∈ R center with the same dimension as W, whose elements satisfy the standard normal distribution of independent and identically distributed: m×n
[0093]
[0094] Step 23: Perform QR decomposition on the generated matrix A according to formula (2.4):
[0095]
[0096] where step (1) generates the orthogonal matrix Q w , step (3) verifies whether the generated orthogonal matrix meets the requirements, and I n represents the identity matrix.
[0097] Step 24: The intermediate layer W center applies the encryption transformation of the orthogonal matrix Q W , and the specific form is:
[0098] W encrypted = Q W ×W center (2.5)
[0099] Step 25: Call the weight after the intermediate layer change W encrypted , and use the AES symmetric encryption algorithm (other encryption algorithms can also be used) to perform secondary encryption on W encrypted , and upload it to the cloud, and at the same time store the private key S corresponding to AES in the private storage space of the encryption dog;
[0100]
[0101] To further enhance security, each dongle generates a pair of ECDSA (Elliptic Curve Digital Signature Algorithm, other signature algorithms can also be used) keys. The private key K is stored in the secure storage area of the dongle, while the public key K is uploaded to the cloud for authentication. Through the ECDSA authentication mechanism, the legitimacy of the dongle can be verified, and it can be ensured that only authorized devices can decrypt the model weights.
[0102] Step 26: As Figure 4 shown, during device initialization, the dongle uses its private key K to sign its own hardware ID and the vulnerable watermark after SHA-256 to generate a unique UUID:
[0103] UUID = Sign(K, hardware ID, SHA-256(vulnerable watermark)) (2.7)
[0104] The public key K is stored in the cloud, and the signature is stored in the private storage area of the dongle for subsequent verification. When the device attempts to access the encrypted model, the server will verify the validity of the UUID and the signature to ensure that only legally authorized devices can correctly decrypt and use the model.
[0105] Step 3: Dongle authorization decryption verification, the flowchart is as Figure 5 shown;
[0106] Step 31: The dongle uses the signature and UUID stored in its private storage area to download the public key K in the cloud through a secure communication channel for verification; if the dongle verification passes, the system allows the subsequent authorization process to continue; if the verification fails, the cloud will immediately send a warning to the model owner, indicating that the model is being illegally authorized, and abort the subsequent authorization process.
[0107] Step 32: After the dongle is verified to be legal, obtain the encrypted model weight W encrypted , from the customer, and obtain the transformation matrix in the cloud and give it to the dongle; the dongle uses its private key S to decrypt the encrypted model weight and restore it to the preliminarily decrypted weight W encrypted ;
[0108] Step 33: The dongle restores the decrypted model weight W encrypted to the original weight W through formula (3.1) final :
[0109]
[0110] Through this restoration process, the dongle will obtain the final weight that can be used for model inference and training.
[0111] Step 34: After the model weight recovery is completed, extract the saved fragile watermark from the model bypass layer; the fragile watermark is encrypted and uploaded to the cloud for comparison; if the two are consistent, the model verification is successful, indicating that the model has not been tampered with; if the comparison fails, the cloud will issue a warning, prompting the model owner that the model may have been tampered with and may cause adverse consequences.
[0112] The deep model security deployment system based on dongle and watermark according to the present invention includes three core modules: a fragile watermark generation module, an authorization encryption module, and a dongle authorization decryption verification module, which are used to implement the authorization verification of the model, the integrity verification, and the legality verification of the dongle;
[0113] The fragile watermark generation module extracts sensitive weights from the model by constructing a 1*1 convolutional bypass layer, scores them, and selects the top 10% of the scores as the fragile watermark, which is stored in the bypass layer and encrypted and uploaded to the cloud;
[0114] The authorization encryption module selects the intermediate layer of the trained model, performs matrix operations using the generated orthogonal matrix A, shuffles and then encrypts the original weights, uploads the encrypted weights to the cloud, and stores the key in the private storage area of the dongle;
[0115] The dongle authorization decryption verification module decrypts the model weights using the stored key after obtaining the authorization qualification in the cloud, and extracts the fragile watermark during the model deployment process; after successful verification, it indicates that the model has not been tampered with, and then deploys the model with successful verification.
[0116] Embodiment:
[0117] In this embodiment, an AI model with a basic CNN architecture is selected, and an embodiment of the method of the present invention is given for the entire process of fragile watermark generation, authorization encryption, and dongle decryption, as Figure 9 shown is the dongle entity used in this embodiment.
[0118] Step 1: Fragile watermark generation
[0119] Step: 11: As Figure 6 shown, select an AI model with a basic CNN architecture; construct a 1*1 convolutional bypass layer parallel to the model structure;
[0120] Step 12: Randomly generate the initial weights of the bypass layer using Randomlnit(). In this embodiment, the weights of the bypass layer for each layer are initialized as: [0.27546746, 0.00316048, 0.27236858, ..., 0.24717516, -0.12034674, -0.24449585]; [-0.16493331, 0.06968803, -0.20987812, …, 0.14410096, -0.19416368, -0.0218972], …, [0.12288336, -0.13894482, -0.14236441, …, 0.08133417, -0.08090314, 0.12418545];
[0121] Step 13: Taking the processing of the vulnerable features of the convolutional layer as an example, read the corresponding weight W;
[0122] Step 14; Sort the extracted weights according to the gradient, as Figure 11 shown respectively as: [0.750132, 0.721755, 0.718040, 0.675492, 0.646908, 0.660179, 0.648264, 0.642436, 0.655336, 0.640956], and the corresponding gradients are: [3.506571, 3.339983, 3.316864, 3.111345, 3.079109, 3.038397, 3.003570, 2.970836, 2.944163, 2.933637];
[0123] Step 15: Use the Hutchinson approximation method to obtain the corresponding maximum eigenvalue. The maximum eigenvalues of the corresponding weights in this example are respectively: [4.588901, 2.100034, 4.311480, 2.824388, 2.641078, 3.805031, 2.431067, 6.316166, 2.665257, 2.505649];
[0124] Step 16: Calculate the product of the maximum eigenvalue and the gradient, and finally obtain the scores S of each weight as:
[0125] [16.177669, 16.581244, 12.681646, 8.873917, 7.277499, 8.411120, 6.307592, 10.721269, 10.143730, 7.607492]
[0126] Step 17: Select the top 10% with the highest scores as the sensitive weights and save them in the bypass layer;
[0127] Step 18: The model bypass layer does not participate in training, and the model is iteratively trained until the model training is completed;
[0128] Step 19: Extract the model weights stored in the bypass layer. For example, after iterative training in this example, the model weights of each bypass layer of the final model are: [-0.13933523, -0.06531993, -0.2620927, …, 0.19189572, -0.0129493, -0.09630706]; [-0.03454703, -0.09373423, -0.03129921, …, -0.02151491, 0.07073014, 0.18999703]; [0.12182633, 0.00177723, 0.1365845,...,, 0.06439178, 0.02971299, -0.0268646];
[0129] Step 110: Standardize the final model weights. The weights after standardization are: [-0.78187674, -0.36247537, -1.4774715, …, 1.095015, -0.06572171, -0.5380613]; [-0.2775559, -0.75004005, -0.25162894, …, -0.17352204, 0.5628589, 1.5149517]; [1.3698484, 0.01229448, 1.5367386, …, 0.72036, 0.328201, -0.31159657];
[0130] Step 111: Concatenate the standardized weights to obtain the final model fragile watermark: [-0.78187674, -0.36247537, -1.4774715, …, 0.72036, 0.328201, -0.31159657]
[0131] Step 112: Hash the model fragile watermark using SHA-256 to obtain a hash string: 2e159861115133dcle2898ld049ee57d4d2b69cal22cldll5274310eal3a8072; Upload the string to the cloud for subsequent anti-tampering verification; As Figure 7 shown, the histogram of the hashed weights is displayed;
[0132] Step 2: Encryption authorization module
[0133] Step 21: Obtain the intermediate layer weights Wc of the model after training is completed enter, in this example, the weights of the middle layer of the model are:
[0134] [[-0.0230, 0.0205, -0.0395, ..., -0.0338, 0.0167, 0.0033],
[0135] [0.0167, 0.0171, 0.0184, ..., 0.0250, 0.0061, -0.0292],
[0136] [-0.0296, -0.0203, 0.0329, ..., 0.0168, -0.0337, -0.0417],
[0137] …,
[0138] [0.0414, 0.0316, 0.0358, ..., 0.0321, 0.0241, 0.0170],
[0139] [-0.0266, 0.0189, 0.0214, ..., -0.0216, -0.0511, -0.0323],
[0140] [0.0082, -0.0768, -0.0201, ..., -0.0142, -0.0192, 0.0107]]
[0141] Step 22: Obtain the number of rows and columns of the middle layer as 128 * 576, and generate a matrix A that follows a normal distribution based on this number of rows and columns:
[0142] [[0.4774, -0.7051, -2.8133, …, 0.5283, -0.1876, 0.2838]
[0143] [1.4668, -0.008, 0.2651, …, -1.4672, 0.1254, 0.941]
[0144] [-0.4, 0.2653, 0.4543, …, 1.6329, 2.2879, 1.3723]
[0145] …
[0146] [-0.219, -0.9592, -0.8738, …, 1.3195, -1.6587, 0.8251]
[0147] [-1.0903, -0.2932, -1.4631, …, 0.9618, -0.3539, -0.5918]
[0148] [[-0.8088, 0.3272, 0.4958… -0.0749, 0.9983, -0.071]]
[0149] Step 23: Obtain the orthogonal matrix Q corresponding to the weights through qa decomposition W :
[0150] [[-0.0447, 0.0702, 0.2457… -0.1134, -0.1122, 0.168]
[0151] [-0.1374, -0.0006, -0.0184… 0.0099, -0.0058, -0.1111]
[0152] [0.0375, -0.0262, -0.0397… -0.1031, 0.0284, -0.0082]
[0153] …
[0154] [0.0205, 0.0964, 0.0694… 0.0239, 0.0026, -0.0978]
[0155] [0.1021, 0.0305, 0.1236… 0.0756, -0.0171, -0.0086]
[0156] [0.0758, -0.032, -0.0443… 0.092, 0.1024, -0.135]
[0157] Step 24: Multiply the orthogonal matrix Q W by the intermediate layer weight W center to obtain the initially encrypted weight:
[0158] [[-0.0191, -0.0701, -0.0284… -0.0062, 0.0123, 0.0431]
[0159] [0.0316, 0.0261, -0.0437… 0.0096, 0.0813, -0.0141]
[0160] [0.0339, 0.0269, 0.0388… 0.0035, 0.0168, -0.008]
[0161] …
[0162] [0.0226, 0.0329, 0.0494… -0.0474, -0.026, 0.0165]
[0163] [0.012 0.032 0.0201…0.0137 -0.0225 0.0053]
[0164] [-0.0018 0.0197 0.002…0.0168 -0.0366 -0.0082]
[0165] As Figure 8 shown, a schematic diagram of weight encryption is presented.
[0166] Step 25: Encrypt the encrypted weights using AES; the partially encrypted ciphertext is as Figure 12 shown; distribute the encrypted file to users who have purchased the product; store the corresponding in the cloud for authorization verification, and place the AES private key in the private storage area of the dongle.
[0167] Step 26: Bind the hardware ID of the dongle, etc. to the hashed model fragile watermark to generate a unique UUID. In this example, the generated unique UUID is: 0ba530bb-de27-564b-8920-d3b2ff64b217, and the public key after signing is: MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEualmQzctVSrkg26qGOSJ94 FK0ePqJ5rDYIVgUnp50Vsc523wnrMAWN6RP4dNOmwgHSD8T+SnGF0 / NLmROzZ4R0 / x09p / ntUKh+aVA8woq3Alg. Then sign the UUID through ECDSA, and the signature is: 975fb4ab5579d 96ef097129d72c181ccf97dafaa4c9ba4349cabe53460ec4ef337916a605b8e001ef01cblf61dcd9d47e0bad3362f806eoalfd3937eblec81ffda5e8760b4f71416dfod2c28ala622cddf5f2773d8e8fc96b98378clle8ef2bb. Store the signature in the dongle storage area, and then upload the corresponding encrypted UUID and public key to the cloud for subsequent verification of the dongle's legality.
[0168] Step 3: Dongle authorization verification
[0169] Step 31: Insert the dongle into the medium that needs to be authorized for deployment, and then download the signature public key for verification. If the verification is successful, continue with the verification. If the verification fails, the administrator will receive a warning of illegal authorization;
[0170] Step 32: Pass the verification, and distribute the matrix in the cloud
[0171] Step 33: The authorized personnel obtain the encrypted weights at the customer's place, and then use the stored AES private key S to decrypt the encrypted weights;
[0172] Step 34: Then use to multiply with the matrix to complete the decryption. In this example, the weights are restored to:
[0173] [[-0.0230, 0.0205, -0.0395,..., -0.0338, 0.0167, 0.0033],
[0174] [0.0167, 0.0171, 0.0184,..., 0.0250, 0.0061, -0.0292],
[0175] [-0.0296, -0.0203, 0.0329,..., 0.0168, -0.0337, -0.0417],
[0176] ...
[0177] [0.0414, 0.0316, 0.0358,..., 0.0321, 0.0241, 0.0170],
[0178] [-0.0266, 0.0189, 0.0214,...,-0.0216, -0.0511, -0.0323],
[0179] [0.0082, -0.0768, -0.0201,...,-0.0142, -0.0192, 0.0107]
[0180] Step 35: Extract the model's fragile watermark, hash it using SHA-256, and upload it to the cloud for comparison with the pre-saved fragile watermark. If the comparison is successful, it indicates that the model has not been tampered with and can be deployed normally; otherwise, it prompts the model owner that the model has been tampered with;
[0181] Step 36: The dongle deploys the tamper-proof verified model to the corresponding physical device, as Figure 10 shown in the deployment result diagram. At this time, the deployment process ensures that the model can only run on authorized devices and always maintains the security constraints of the dongle on that device.
Claims
1. A method for securely deploying a deep model based on a dongle and watermark, characterized in that, It includes the following steps: Step 1: Generate a fragile watermark; Step 2: Authorize the encryption algorithm; Step 3: Perform authorization decryption verification on the dongle.
2. The method for securely deploying a deep model based on a dongle and watermark according to claim 1, wherein The said Step 1 includes: Step 11: Construct a bypass layer of 1*1 convolution according to the model and initialize the weights W of the bypass layer bypass ; Step 12: Read the model weights W; Step 13: Sort W according to the absolute value of the gradient, select the top 30% with the largest gradient values as the initial weights, and use W l to represent the weight of the l-th layer among the selected weights, and use G l to represent the gradient corresponding to the l-th layer; Step 14: Calculate W using the approximate Hessian matrix method i The maximum eigenvalue λ max ; Step 15: Calculate the final score S of the sensitivity weight for each layer according to formula (1.1) l : S l = λ max ·G l (1.1) Step 16: Select S l The top 10% of the weights in Step 17: The bypass layer in the model does not participate in training, that is The bypass layer is calculated according to formula (1.2): O bypass = X * W bypass = 0 (1.2) Among them, * represents the convolution operation, and O bypass represents the output of this bypass layer.
3. The method for securely deploying a deep model based on a dongle and watermark according to claim 2, wherein After the iterative training of the model is completed, the sensitive weights of each layer stored in the bypass layer are extracted using formula (1.3). represents the gradient matrix of this layer; Normalize the weights using formula (1.4), combine the model watermarks of each layer through formula (1.5) to form a fragile watermark, and finally encrypt the fragile watermark using SHA-256 and upload it to the cloud: Among them, μ l represents the mean of the sensitive weights of the l-th layer, and σ l represents the standard deviation of the sensitive weights of the l-th layer. W fragile represents the final fragile watermark.
4. The method for securely deploying a deep model based on a dongle and watermark according to claim 1, wherein, The said Step 2 includes: Step 21: Obtain the trained complete model weights W final of the intermediate layer W center , W final generated by formula (2.1), W center obtained using formula (2.2): W final = {W main , W bypass} (2.1) Among them, W main is the weight of the main task; Step 22: Generate a random matrix A ∈ R center with the same dimension as W m×n , whose elements satisfy the standard normal distribution of independent and identically distributed: Step 23: Perform QR decomposition on the generated matrix A according to formula (2.4): Among them, in step (1), an orthogonal matrix Q is generated w , in step (3), it is verified whether the generated orthogonal matrix meets the requirements, and I n represents the identity matrix Step 24: Intermediate layer W center Apply the orthogonal matrix Q W for the encryption transformation, and the specific form is: W encrypted = Q W × W center (2.5) Step 25: Name the weights that have undergone intermediate layer changes as W encrypted , and use an encryption algorithm to encrypt W encrypted , and upload to the cloud. At the same time, store the private key S corresponding to AES in the private storage space of the encryption dog; Step 26: Use the hardware ID of the dongle to bind it to the fragile watermark to generate a unique UUID.
5. The method for securely deploying a deep model based on a dongle and watermark according to claim 4, characterized in that, The said Step 26 includes: Implement it using the ECDSA signature algorithm, then store the corresponding verification private key K in the private storage area of the dongle. In the verification, first verify the signature to ensure the legality of the dongle, and then further authorize.
6. The method for securely deploying a deep model based on a dongle and watermark according to claim 4, wherein The encryption algorithm in the said Step 25 includes the AES encryption algorithm and the ChaCha20 encryption algorithm.
7. The method for securely deploying a deep model based on a dongle and watermark according to claim 1, wherein The said Step 3 includes: Step 31: The dongle uses the signature and UUID stored in its private storage area to download the public key K in the cloud through a secure communication channel for verification; Step 32: After the dongle is verified to be legal, obtain the encrypted model weights W from the customer encrypted , and obtain the transformation matrix in the cloud and give it to the dongle; the dongle decrypts the encrypted model weights using its private key S and restores them to the preliminarily decrypted weights W encrypted ; Step 33: The dongle restores the decrypted model weights W encrypted to the original weights W through formula (3.1) final : Through this recovery process, the dongle will obtain the final weights that can be used for model inference and training. Step 34: After the model weight recovery is completed, extract the saved fragile watermark from the model bypass layer; the fragile watermark is encrypted and uploaded to the cloud for comparison; Step 35: The dongle deploys the tamper-proof verified model to the corresponding physical device.
8. The method for securely deploying a deep model based on a dongle and watermark according to claim 7, wherein The said Step 31 verifies its legality according to the UUID and signature of the dongle. If the dongle verification passes, the system allows the subsequent authorization process to continue; If the verification fails, the cloud will immediately send a warning to the model owner, indicating that the model is being illegally authorized, and abort the subsequent authorization process.
9. The method for securely deploying a deep model based on a dongle and watermark according to claim 7, wherein The fragile watermark in the said Step 34 is encrypted and uploaded to the cloud for comparison. If the two are consistent, the model verification is successful, indicating that the model has not been tampered with; if the comparison fails, the cloud will issue a warning, prompting the model owner that the model may have been tampered with and may cause adverse consequences.
10. A deep model security deployment system based on a dongle and watermark, characterized in that, It includes three core modules: a fragile watermark generation module, an authorization encryption module, and a dongle authorization decryption verification module, which are used to implement model authorization verification, integrity verification, and dongle legality verification; The fragile watermark generation module extracts sensitive weights from the model by constructing a 1*1 convolutional bypass layer, scores them, and selects the top 10% with the highest scores as the fragile watermark, stores it in the bypass layer and encrypts it and uploads it to the cloud; The authorization encryption module selects the intermediate layer of the trained model, performs matrix operations using the generated orthogonal matrix A, shuffles the original weights and then encrypts them, uploads the encrypted weights to the cloud, and stores the key in the private storage area of the dongle; The dongle authorization decryption verification module, after the dongle obtains the authorization qualification in the cloud, decrypts the model weights using the stored key and extracts the fragile watermark during the model deployment process; After successful verification, it indicates that the model has not been tampered with, and then the successfully verified model is deployed.
Citation Information
Patent Citations
Signature watermark system used for CAD (Computer-Aided Design) documents
CN102117476A
Cloud data security protection method adopting fully homomorphic encryption technology and multiple digital watermarking technology
CN105323209A
Video copyright protection method and system based on block chain and digital watermarking technology
CN114003871A
Neural network model security protection and integrity verification method and system
CN115408699A
Integrity authentication semi-fragile watermarking method for three-dimensional geometric model cloud storage
CN115422599A