Protecting the intellectual property (IP) of deep neural network (DNN) models becomes essential and urgent with rapidly increasing cost DNN training. Fingerprinting is one promising IP protection method that queries suspicious specific fingerprint samples to infer verify by comparing predictions pre-defined labels. Based on utilizing unique features target models, various fingerprinting methods...