Tolerance of CNN watermarking against model optimizations

Tolerance of CNN watermarking against model optimizations
复制标题

CNN 水印对模型优化的容忍度

DOI:
10.1117/12.2625769
复制
发表时间:
2022
期刊:
SPIE Proceedings Vol. 12177: International Workshop on Advanced Imaging Technology (IWAIT) 2022
影响因子:
--
通讯作者:
Sakazawa Shigeyuki
Sakazawa Shigeyuki
中科院分区:
--
文献类型:
--
作者:
Yamaji Yudai;Sakazawa Shigeyuki

文献摘要

被引文献

相似文献

公司和个人通过训练大量数据创建的模型是重要的资产,需要受到版权保护。作为版权保护的方法,实验已经进行了嵌入水印到学习模型。该水印被直接嵌入到学习模型的参数中,但是当学习模型经受诸如量化的模型压缩处理时,参数的值将改变。在我们之前的研究中,我们证明了量化对水印的影响很小,并且嵌入的水印可以被检索。在本文中,作为进一步的调查,我们进行实验的效果修剪和量化,量化意识的训练时,创建训练模型的水印。在实验中,我们使用了一大一小两种不同尺度的模型,并对每个模型执行上述处理以检查水印的状态。结果表明,修剪和量化的模型表现出显着的小规模模型的水印退化,但这是消除模型量化。在量化感知训练的情况下,对水印没有影响。
Models created by companies and individuals by training a large amount of data are important assets and need to be protected by copyright. As a method of copyright protection, experiments have been conducted to embed a watermark into the learning model. This watermark is embedded directly into the parameters of the learning model, but the values of the parameters will change when the learning model is subjected to model compression process such as quantization. In our previous study, we showed that the effect of quantization on the watermark was small and that the embedded watermark could be retrieved. In this paper, as a further investigation, we conduct experiments on the effect of both pruning and quantization, and quantization aware training on the watermarking when creating the trained model. In the experiments, we used models of two different scales, one large and one small, and performed the above-mentioned processing on each model to check the state of the watermark. The results show that the models with both pruning and quantization show significant degradation of the watermark for small-scale models, but this is eliminated when the models are quantized. In the case of quantization aware training, there was no effect on watermarking.