Piracy-Resistant DNN Watermarking by Block-Wise Image Transformation with Secret Key

Piracy-Resistant DNN Watermarking by Block-Wise Image Transformation with Secret Key
复制标题

通过使用密钥的分块图像变换实现防盗版 DNN 水印

DOI:
10.1145/3437880.3460398
复制
发表时间:
2021
期刊:
Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security
影响因子:
--
通讯作者:
H. Kiya
H. Kiya
中科院分区:
--
文献类型:
--
作者:
Maungmaung Aprilpyone;H. Kiya

文献摘要

被引文献

相似文献

在本文中,我们提出了一种新的DNN水印方法,利用一个可学习的图像变换方法与密钥。该方法通过使用可学习的变换图像在模型中嵌入水印模式,并允许我们远程验证模型的所有权。因此,它是防盗版的,因此原始水印不能被盗版水印覆盖,并且与大多数现有的DNN水印方法不同,添加新水印会降低模型精度。此外,它不需要特殊的预定义训练集或触发集。我们在CIFAR-10数据集上对所提出的方法进行了经验评估。实验结果表明,该算法在保持较高水印检测精度的同时,对微调和剪枝攻击具有较强的抵抗能力。
In this paper, we propose a novel DNN watermarking method that utilizes a learnable image transformation method with a secret key. The proposed method embeds a watermark pattern in a model by using learnable transformed images and allows us to remotely verify the ownership of the model. As a result, it is piracy-resistant, so the original watermark cannot be overwritten by a pirated watermark, and adding a new watermark decreases the model accuracy unlike most of the existing DNN watermarking methods. In addition, it does not require a special pre-defined training set or trigger set. We empirically evaluated the proposed method on the CIFAR-10 dataset. The results show that it was resilient against fine-tuning and pruning attacks while maintaining a high watermark-detection accuracy.