NN Traceability Technologies enable tracking of identities of some Actors and the Modifications to the NN effected by them. Typically, a Neural Network service involves the following Actors:
- Architect: designs the architecture of the model
- Trainer: trains the model for a purpose
- Tracker: provides the tracking technology
- Distributor: distributes trained model with tracking technology
- Generic user: any user intended by the Distributor
- Attacker: any user, be they intended or not by the Distributor, that applies a modification to the Neural Network subjected to the Traceability Technology.
Examples of typical Modifications applied to Neural Networks (in the following usually abbreviated to NN) are finetuning, pruning, and quantizing.
A variety of methods have been developed for Neural Network Traceability since 2017, especially for watermarking. They can be divided into two categories:
- Watermarking methods, Active methods which alter the Weights of the NN to insert Traceability Data.
- Fingerprinting methods, Passive methods which do not alter the Weights of the NN.
MPAI has developed two Neural Network Traceability standards:
- Technical Specification: Neural Network Watermarking (MPAI-NNW) V1.0 provides tools to evaluate Watermarking methods, for a given Payload, on three properties: Imperceptibility, Robustness, and Computational Cost [2].
- Technical Specification: Neural Network Watermarking (MPAI-NNW) – Neural Network Traceability (NNW-NNT) V1.0 provides tools to evaluate both categories of Traceability methods keeping the methods included in MPAI-NNW V1.0 [2].
This Technical Specification: Neural Network Watermarking (MPAI-NNW) – Neural Network Traceability Technologies (NNW-TEC) V1.0 additionally assesses specific NN Traceability technologies with respect to Imperceptibility, Robustness, and Computational Cost using methodologies specified by NNW-NNT V1.0.
Capitalised Terms are defined in Table 1. All MPAI-defined Terms are accessible online.
All Chapters and Sections are Normative unless they are labelled as Informative.