arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.31968cs.CR

硬件根植的PUF指纹识别:用于知识蒸馏中设备级可追溯性

Hardware-Rooted PUF Fingerprinting for Device-Level Traceability in Knowledge Distillation

  • Lehigh University(利哈伊大学)
  • Broadcom Inc.(博通公司)

机构由 AI 辅助整理,请以论文原文为准。

Ning Lyu, Yuntao Liu, Yonghong Bai, Zhiyuan Yan

AI总结:

本文提出一种基于PUF的指纹框架,在知识蒸馏中将设备签名叠加到教师logits上,使学生模型继承硬件身份,实现抗篡改的设备级可追溯性。

AI中文摘要:

知识蒸馏(KD)能够在异构平台和部署环境之间实现模型迁移,然而它也使得专有模型面临基于蒸馏的盗窃风险,即攻击者通过利用教师模型的输出训练学生模型来提取知识产权(IP)。现有的防御措施,如软件水印或基于硬件的访问控制,要么无法在蒸馏过程中幸存,要么缺乏识别泄露来源具体设备的粒度。为了提供事后问责和可追溯性,我们提出了一种新颖的指纹识别框架,该框架在蒸馏过程中将设备特定的物理不可克隆函数(PUF)签名叠加到教师模型的logits上。通过利用在Xilinx Zynq-7020 FPGA上测量的环形振荡器(RO)PUF生成的签名,我们确保任何通过KD训练的学生模型都继承一个独特的、与硬件关联的身份。我们的框架与架构无关,能够在异构结构(包括卷积神经网络、视觉变换器和编码器)中实现可靠的身份继承。为了确保稳健的属性归因,我们实现了一个两阶段恢复流程,包括神经解码器和汉明距离细化,即使在噪声条件下也能保持高检测精度。此外,我们引入了一种多级logit编码方案,以支持大规模设备部署。实验结果表明,嵌入的指纹对常见的蒸馏后修改具有弹性。这些结果为在分布式AI部署环境中实现硬件关联的模型可追溯性建立了一种实用的系统级方法。

英文摘要:

Knowledge distillation (KD) enables model transfer across heterogeneous platforms and deployment environments, yet it exposes proprietary models to distillation-based theft, where an adversary extracts intellectual property (IP) by training a student model on teacher outputs. Current defenses, such as software watermarking or hardware-based access control, either fail to survive the distillation process or lack the granularity to identify the specific device responsible for a leak. Aiming to provide post-theft accountability and traceability, we propose a novel fingerprinting framework that superimposes device-specific Physical Unclonable Function (PUF) signatures onto teacher logits during distillation. By utilizing signatures derived from Ring Oscillator (RO) PUFs measured on a Xilinx Zynq-7020 FPGA, we ensure that any student model trained via KD inherits a unique, hardware-linked identity. Our framework is architecture-agnostic, enabling reliable identity inheritance across heterogeneous structures, including Convolutional Neural Networks, Vision Transformers, and encoders. To ensure robust attribution, we implement a two-stage recovery pipeline consisting of a neural decoder and Hamming-distance refinement, maintaining high detection accuracy even under noisy conditions. Furthermore, we introduce a multi-level logit encoding scheme to support large-scale device deployment. Experimental results demonstrate that the embedded fingerprints are resilient against common post-distillation modifications. These results establish a practical system-level approach for enabling hardware-linked model traceability in distributed AI deployment environments.

↑