In response to the growing popularity of Machine Learning (ML) techniques to solve problems in various industries, various malicious groups have started to target such techniques in their attack plan. However, as ML models are constantly updated with continuous data, it is very hard to monitor the integrity of ML models. One probable solution would be to use hashing techniques. Regardless of how that would mean re-hashing the model each time the model is trained on newer data which is computationally expensive and not a feasible solution for ML models that are trained on continuous data. Therefore, in this paper, we propose a model integrity-checking mechanism that uses model watermarking techniques to monitor the integrity of ML models. We then demonstrate that our proposed technique can monitor the integrity of ML models even when the model is further trained on newer data with a low computational cost. Furthermore, the integrity checking mechanism can be used on Deep Learning models that work on complex data distributions such as Cyber-Physical System applications.
翻译:随着机器学习(ML)技术在各行各业解决实际问题中的日益普及,各类恶意团体已开始将此类技术纳入其攻击计划。然而,由于ML模型需持续基于新数据进行更新,其完整性监控极为困难。一种可行的解决方案是采用哈希技术,但这意味着每次模型基于新数据训练后都需重新计算哈希值,计算成本高昂,且对于持续接收数据的ML模型而言并不可行。因此,本文提出一种利用模型水印技术的模型完整性检查机制,用于监控ML模型的完整性。我们证明,即使模型基于新数据进一步训练,该机制仍能以较低计算成本监控其完整性。此外,该完整性检查机制可应用于处理复杂数据分布的深度学习模型,例如网络-物理系统应用。