{"id":"https://openalex.org/W7135042099","doi":"https://doi.org/10.48550/arxiv.2603.10753","title":"A PUF-Based Approach for Copy Protection of Intellectual Property in Neural Network Models","display_name":"A PUF-Based Approach for Copy Protection of Intellectual Property in Neural Network Models","publication_year":2026,"publication_date":"2026-03-11","ids":{"openalex":"https://openalex.org/W7135042099","doi":"https://doi.org/10.48550/arxiv.2603.10753"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.10753","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.10753","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.10753","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5066487316","display_name":"Daniel Dorfmeister","orcid":"https://orcid.org/0000-0002-2718-6007"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Dorfmeister, Daniel","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035972346","display_name":"Flavio Ferrarotti","orcid":"https://orcid.org/0000-0003-2278-8233"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ferrarotti, Flavio","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067067730","display_name":"B. Fischer","orcid":"https://orcid.org/0000-0001-9737-0056"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Fischer, Bernhard","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5095374388","display_name":"Martin Schwandtner","orcid":"https://orcid.org/0009-0005-6568-4786"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Schwandtner, Martin","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5044337073","display_name":"Hannes Sochor","orcid":"https://orcid.org/0000-0001-6238-6293"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sochor, Hannes","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5066487316"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.0005000000237487257,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.00039999998989515007,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/copying","display_name":"Copying","score":0.6762999892234802},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.6442999839782715},{"id":"https://openalex.org/keywords/intellectual-property","display_name":"Intellectual property","score":0.5435000061988831},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.5015000104904175},{"id":"https://openalex.org/keywords/property","display_name":"Property (philosophy)","score":0.4580000042915344},{"id":"https://openalex.org/keywords/rendering","display_name":"Rendering (computer graphics)","score":0.41339999437332153}],"concepts":[{"id":"https://openalex.org/C2779151265","wikidata":"https://www.wikidata.org/wiki/Q1156791","display_name":"Copying","level":2,"score":0.6762999892234802},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6552000045776367},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.6442999839782715},{"id":"https://openalex.org/C34974158","wikidata":"https://www.wikidata.org/wiki/Q131257","display_name":"Intellectual property","level":2,"score":0.5435000061988831},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.5015000104904175},{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.4580000042915344},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4406999945640564},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.41769999265670776},{"id":"https://openalex.org/C205711294","wikidata":"https://www.wikidata.org/wiki/Q176953","display_name":"Rendering (computer graphics)","level":2,"score":0.41339999437332153},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3903999924659729},{"id":"https://openalex.org/C2780615836","wikidata":"https://www.wikidata.org/wiki/Q2471869","display_name":"USable","level":2,"score":0.33570000529289246},{"id":"https://openalex.org/C8643368","wikidata":"https://www.wikidata.org/wiki/Q4046262","display_name":"Physical unclonable function","level":3,"score":0.3337000012397766},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.2994999885559082},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.28610000014305115},{"id":"https://openalex.org/C2778348673","wikidata":"https://www.wikidata.org/wiki/Q739302","display_name":"Production (economics)","level":2,"score":0.2786000072956085},{"id":"https://openalex.org/C2781162219","wikidata":"https://www.wikidata.org/wiki/Q26250693","display_name":"Replicate","level":2,"score":0.27390000224113464}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.10753","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.10753","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.10753","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.10753","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"More":[0],"and":[1,37,43,68,98,152],"more":[2],"companies'":[3],"Intellectual":[4],"Property":[5],"(IP)":[6],"is":[7],"being":[8],"integrated":[9],"into":[10],"Neural":[11],"Network":[12],"(NN)":[13],"models.":[14],"This":[15],"IP":[16,72],"has":[17],"considerable":[18],"value":[19],"for":[20,93],"companies":[21],"and,":[22],"therefore,":[23],"requires":[24],"adequate":[25],"protection.":[26],"For":[27,81],"example,":[28],"an":[29,61,86],"attacker":[30],"might":[31],"replicate":[32],"a":[33],"production":[34],"machines'":[35],"hardware":[36,57,100,120,135],"subsequently":[38],"simply":[39],"copy":[40],"associated":[41],"software":[42],"NN":[44,53,65,87,131,150],"models":[45,54,66,151],"onto":[46,55],"the":[47,71,118,123,130,143],"cloned":[48,56,134],"hardware.":[49,80],"To":[50],"make":[51],"copying":[52],"infeasible,":[58],"we":[59,84],"present":[60],"approach":[62,141],"to":[63,77,96,121],"bind":[64],"-":[67,76],"thus":[69],"also":[70],"contained":[73],"within":[74],"them":[75],"their":[78],"underlying":[79],"this":[82],"purpose,":[83],"link":[85],"model's":[88],"weights,":[89,125],"which":[90],"are":[91],"crucial":[92],"its":[94],"operation,":[95],"unique":[97],"unclonable":[99],"properties":[101],"by":[102],"leveraging":[103],"Physically":[104],"Unclonable":[105],"Functions":[106],"(PUFs).":[107],"By":[108],"doing":[109],"so,":[110],"sufficient":[111],"accuracy":[112,147],"can":[113],"only":[114],"be":[115],"achieved":[116],"using":[117],"target":[119],"restore":[122],"original":[124],"rendering":[126],"proper":[127],"execution":[128],"of":[129,146],"model":[132],"on":[133,148],"impossible.":[136],"We":[137],"demonstrate":[138],"that":[139],"our":[140],"accomplishes":[142],"desired":[144],"degradation":[145],"various":[149],"outline":[153],"possible":[154],"future":[155],"improvements.":[156]},"counts_by_year":[],"updated_date":"2026-03-13T14:25:03.468858","created_date":"2026-03-13T00:00:00"}
