Deep Model Intellectual Property Protection via Deep Watermarking

03/08/2021
by   Jie Zhang, et al.
6

Despite the tremendous success, deep neural networks are exposed to serious IP infringement risks. Given a target deep model, if the attacker knows its full information, it can be easily stolen by fine-tuning. Even if only its output is accessible, a surrogate model can be trained through student-teacher learning by generating many input-output training pairs. Therefore, deep model IP protection is important and necessary. However, it is still seriously under-researched. In this work, we propose a new model watermarking framework for protecting deep networks trained for low-level computer vision or image processing tasks. Specifically, a special task-agnostic barrier is added after the target model, which embeds a unified and invisible watermark into its outputs. When the attacker trains one surrogate model by using the input-output pairs of the barrier target model, the hidden watermark will be learned and extracted afterwards. To enable watermarks from binary bits to high-resolution images, a deep invisible watermarking mechanism is designed. By jointly training the target model and watermark embedding, the extra barrier can even be absorbed into the target model. Through extensive experiments, we demonstrate the robustness of the proposed framework, which can resist attacks with different network structures and objective functions.

READ FULL TEXT

page 2

page 5

page 6

page 7

page 9

page 11

page 13

research
02/25/2020

Model Watermarking for Image Processing Networks

Deep learning has achieved tremendous success in numerous industrial app...
research
08/05/2021

Exploring Structure Consistency for Deep Model Watermarking

The intellectual property (IP) of Deep neural networks (DNNs) can be eas...
research
03/20/2023

Model Barrier: A Compact Un-Transferable Isolation Domain for Model Intellectual Property Protection

As scientific and technological advancements result from human intellect...
research
10/29/2020

Passport-aware Normalization for Deep Model Protection

Despite tremendous success in many application scenarios, deep learning ...
research
11/24/2022

CycleGANWM: A CycleGAN watermarking method for ownership verification

Due to the proliferation and widespread use of deep neural networks (DNN...
research
03/31/2019

BlackMarks: Blackbox Multibit Watermarking for Deep Neural Networks

Deep Neural Networks have created a paradigm shift in our ability to com...
research
07/16/2019

Prediction of neural network performance by phenotypic modeling

Surrogate models are used to reduce the burden of expensive-to-evaluate ...

Please sign up or login with your details

Forgot password? Click here to reset