ProIP-D2FDM: Protecting Intellectual Property of Deepfake Fingerprint Detection Model on Cross-Material Generalization
Constructing a deepfake fingerprint detection model (D2FDM) to counteract spoofing attacks stemming from forged fingerprints is a formidable challenge, requiring massive fingerprint samples, computing resources, and profound professional expertise. Consequently, it is of paramount importance to formulate an effective strategy to protect the intellectual property (IP) of D2FDM. To achieve this, this paper proposes a practical ProIP-D2FDM framework to authenticate the D2FDM. Firstly, the identity of model ownership is hidden in the cross-material fingerprint using generative steganography. The generated invisible additive noise serves as a watermark, rendering the backdoor inconspicuous, and facilitating its embedding through collaborative training with the original fingerprint dataset. Then, the key trigger set is constructed by sampling the original fake fingerprints, and the target label of the trigger set is employed as the foundation for IP verification. Once authorized, the embedded identity can also be distributed. Finally, to prevent the functionality of D2FDM from being stolen via distillation attacks, this paper further designs a novel non-distillable strategy. In this strategy, the student model is deprived of any prior knowledge acquisition. Experimental results demonstrate that our method achieves a remarkable 100% watermark verification accuracy and 100% success rate in user identity authentication on D2FDM trained using two public fingerprint datasets, namely LivDet2017 and LivDet2019. When the non-distillable strategy devised in this paper is used, the performance of the student model, with the D2FDM as the teacher model, exhibits a 4% decline. Moreover, the framework presented in this paper shows remarkable robustness against several common attacks.
Read more