{"id":"https://openalex.org/W7140236685","doi":"https://doi.org/10.48550/arxiv.2603.21411","title":"Fingerprinting Deep Neural Networks for Ownership Protection: An Analytical Approach","display_name":"Fingerprinting Deep Neural Networks for Ownership Protection: An Analytical Approach","publication_year":2026,"publication_date":"2026-03-22","ids":{"openalex":"https://openalex.org/W7140236685","doi":"https://doi.org/10.48550/arxiv.2603.21411"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.21411","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.21411","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.21411","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Yang, Guang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yang, Guang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Geng, Ziye","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Geng, Ziye","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Chen, Yihang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Yihang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":null,"display_name":"Luo, Changqing","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Luo, Changqing","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9746999740600586,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9746999740600586,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.003599999938160181,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.002899999963119626,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.7565000057220459},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.6292999982833862},{"id":"https://openalex.org/keywords/uniqueness","display_name":"Uniqueness","score":0.5530999898910522},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5170000195503235},{"id":"https://openalex.org/keywords/upper-and-lower-bounds","display_name":"Upper and lower bounds","score":0.476500004529953},{"id":"https://openalex.org/keywords/interval","display_name":"Interval (graph theory)","score":0.42179998755455017},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.34860000014305115},{"id":"https://openalex.org/keywords/decision-boundary","display_name":"Decision boundary","score":0.32820001244544983}],"concepts":[{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.7565000057220459},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.652999997138977},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.6292999982833862},{"id":"https://openalex.org/C2777021972","wikidata":"https://www.wikidata.org/wiki/Q22976830","display_name":"Uniqueness","level":2,"score":0.5530999898910522},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5170000195503235},{"id":"https://openalex.org/C77553402","wikidata":"https://www.wikidata.org/wiki/Q13222579","display_name":"Upper and lower bounds","level":2,"score":0.476500004529953},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.45680001378059387},{"id":"https://openalex.org/C2778067643","wikidata":"https://www.wikidata.org/wiki/Q166507","display_name":"Interval (graph theory)","level":2,"score":0.42179998755455017},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.41190001368522644},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.392300009727478},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.34860000014305115},{"id":"https://openalex.org/C42023084","wikidata":"https://www.wikidata.org/wiki/Q5249231","display_name":"Decision boundary","level":3,"score":0.32820001244544983},{"id":"https://openalex.org/C184898388","wikidata":"https://www.wikidata.org/wiki/Q1435712","display_name":"Pairwise comparison","level":2,"score":0.328000009059906},{"id":"https://openalex.org/C62354387","wikidata":"https://www.wikidata.org/wiki/Q875399","display_name":"Boundary (topology)","level":2,"score":0.3237999975681305},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3111000061035156},{"id":"https://openalex.org/C2780186347","wikidata":"https://www.wikidata.org/wiki/Q11414","display_name":"Subnetwork","level":2,"score":0.2842000126838684},{"id":"https://openalex.org/C191252586","wikidata":"https://www.wikidata.org/wiki/Q1671453","display_name":"Interval arithmetic","level":3,"score":0.2777000069618225},{"id":"https://openalex.org/C19768560","wikidata":"https://www.wikidata.org/wiki/Q320727","display_name":"Dependency (UML)","level":2,"score":0.27549999952316284},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.2711000144481659},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.27070000767707825},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.2669000029563904},{"id":"https://openalex.org/C187691185","wikidata":"https://www.wikidata.org/wiki/Q2020720","display_name":"Grid","level":2,"score":0.2646999955177307},{"id":"https://openalex.org/C63584917","wikidata":"https://www.wikidata.org/wiki/Q333286","display_name":"Bounding overwatch","level":2,"score":0.260699987411499}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.21411","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.21411","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.21411","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.21411","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.6655132174491882}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Adversarial-example-based":[0],"fingerprinting":[1,89],"approaches,":[2],"which":[3,76,142],"leverage":[4],"the":[5,38,58,61,104,125,131,143,154,158,168,192,197,201,205,213,218],"decision":[6,39],"boundary":[7,40],"characteristics":[8],"of":[9,60,130,172],"deep":[10],"neural":[11],"networks":[12],"(DNNs)":[13],"to":[14,41,190,196,216],"craft":[15],"fingerprints,":[16],"have":[17],"proven":[18],"effective":[19,52,234],"for":[20,51],"model":[21,182,239,242],"ownership":[22,55,235],"protection.":[23,56],"However,":[24],"a":[25,32,67,108,150,186],"fundamental":[26],"challenge":[27],"remains":[28],"unresolved:":[29],"how":[30],"far":[31],"fingerprint":[33,100,164],"should":[34],"be":[35],"placed":[36],"from":[37],"simultaneously":[42],"satisfy":[43],"two":[44,155,179],"essential":[45],"properties,":[46],"i.e.,":[47],"robustness":[48,80,115],"and":[49,53,70,116,127,157,174,184,204,241],"uniqueness,":[50,117],"reliable":[54],"Despite":[57],"importance":[59],"fingerprint-to-boundary":[62,105,159],"distance,":[63],"existing":[64],"works":[65],"lack":[66],"theoretical":[68,95,151],"solution":[69],"instead":[71],"rely":[72],"on":[73],"empirical":[74],"heuristics,":[75],"may":[77],"violate":[78],"either":[79],"or":[81],"uniqueness":[82],"properties.":[83],"We":[84],"propose":[85],"AnaFP,":[86],"an":[87,138],"analytical":[88],"scheme":[90],"that":[91,123,227],"constructs":[92],"fingerprints":[93],"under":[94],"guidance.":[96],"Specifically,":[97],"we":[98,118,166,208],"formulate":[99],"generation":[101],"as":[102],"controlling":[103],"distance":[106],"through":[107],"tunable":[109],"stretch":[110,132,144,206,221],"factor.":[111,133,222],"To":[112,161],"ensure":[113],"both":[114],"mathematically":[119],"formalize":[120],"these":[121],"properties":[122],"determine":[124,217],"lower":[126,202],"upper":[128],"bounds":[129,135],"These":[134],"jointly":[136],"define":[137],"admissible":[139,214],"interval":[140,215],"within":[141],"factor":[145],"must":[146],"lie,":[147],"thereby":[148],"establishing":[149],"connection":[152],"between":[153,200],"constraints":[156],"distance.":[160],"enable":[162],"practical":[163],"generation,":[165],"approximate":[167],"original":[169],"(infinite)":[170],"sets":[171],"pirated":[173],"independently":[175],"trained":[176],"models":[177],"using":[178],"finite":[180],"surrogate":[181],"pools":[183],"employ":[185],"quantile-based":[187],"relaxation":[188],"strategy":[189],"relax":[191],"derived":[193],"bounds.":[194],"Due":[195],"circular":[198],"dependency":[199],"bound":[203],"factor,":[207],"apply":[209],"grid":[210],"search":[211],"over":[212],"most":[219],"feasible":[220],"Extensive":[223],"experimental":[224],"results":[225],"show":[226],"AnaFP":[228],"consistently":[229],"outperforms":[230],"prior":[231],"methods,":[232],"achieving":[233],"verification":[236],"across":[237],"diverse":[238],"architectures":[240],"modification":[243],"attacks.":[244]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-25T00:00:00"}
