A spatiotemporal chaos based deep learning model watermarking scheme

被引:2
作者
Wang, Dehui [1 ]
Zhou, Shuang [2 ]
Zhang, Yingqian [3 ,4 ]
机构
[1] Beihang Univ, Sch Math Sci, Beijing 100000, Peoples R China
[2] Chongqing Normal Univ, Sch Math Sci, Chongqing 401331, Peoples R China
[3] Xiamen Univ, Tan Kah Kee Coll, Sch Informat Sci & Technol, Zhangzhou 363105, Peoples R China
[4] Xiamen Univ Malaysia, Sch EEAI, Sepang 43900, Selangor, Malaysia
基金
中国国家自然科学基金;
关键词
Deep learning; Spatiotemporal chaos; Watermarking; Intellectual property protection; Chaotic annotation;
D O I
10.1016/j.asoc.2024.112004
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With deep learning techniques achieving great results in modern industry, the intellectual property (IP) protection for deep learning models has attracted the attention of academics and engineers. However, training a commercially viable deep learning model usually needs professional resources and time. Once a malicious user clones, illegally distributes and uses the model, it can infringe on the model owner's IP and even steal its market share. Among the existing IP protection methods, scholars prefer the black-box watermarking approaches, of which the content of the trigger set and the label are the key part of the watermarking technique. However, most schemes do not consider the security and invisibility of the trigger set, which allows attackers to easily trigger the model by creating a fake trigger set, thereby committing a fraudulent ownership claim attack and claiming the ownership belongs to themselves. To overcome these drawbacks, we proposed a spatiotemporal chaotic data annotation method. Firstly, the unpredictability and acyclicity of chaos make the model resistant to fraudulent ownership claim attacks, statistical inference and other common machine learning attacks; Secondly, the trigger set and parameters are independent of each other, guaranteeing the security of the key; Thirdly, the spatiotemporal chaotic system provides a large key space, which meets the commercialization needs of deep learning models. Theoretical analysis and experimental results show that our scheme has security, practicality and robustness. To further validate the superiority of the proposed method, we also compare it with the Logistic chaotic annotation watermarking-based method, and the results show that our method performs better in terms of robustness, effectiveness, completeness, fidelity, security and practicality.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Abdi H., 2007, Encyclopedia of measurement and statistics, V2, P508, DOI DOI 10.4135/9781412952644.N239
  • [2] Adi Y, 2018, PROCEEDINGS OF THE 27TH USENIX SECURITY SYMPOSIUM, P1615
  • [3] A symmetric image encryption scheme based on 3D chaotic cat maps
    Chen, GR
    Mao, YB
    Chui, CK
    [J]. CHAOS SOLITONS & FRACTALS, 2004, 21 (03) : 749 - 761
  • [4] Security measurement of a medical communication scheme based on chaos and DNA coding
    Chen, Lei
    Li, Chengqing
    Li, Chao
    [J]. JOURNAL OF VISUAL COMMUNICATION AND IMAGE REPRESENTATION, 2022, 83
  • [5] WMNet: A Lossless Watermarking Technique Using Deep Learning for Medical Image Authentication
    Chen, Yueh-Peng
    Fan, Tzuo-Yau
    Chao, Her-Chang
    [J]. ELECTRONICS, 2021, 10 (08)
  • [6] Rouhani BD, 2018, Arxiv, DOI arXiv:1804.00750
  • [7] Robust and secured watermarking using Ja-Fi optimization for digital image transmission in social media
    Devi, K. Jyothsna
    Singh, Priyanka
    Thakkar, Hiren Kumar
    Kumar, Neeraj
    [J]. APPLIED SOFT COMPUTING, 2022, 131
  • [8] BNAS-v2: Memory-Efficient and Performance-Collapse-Prevented Broad Neural Architecture Search
    Ding, Zixiang
    Chen, Yaran
    Li, Nannan
    Zhao, Dongbin
    [J]. IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2022, 52 (10): : 6259 - 6272
  • [9] Secure Control of Networked Control Systems Using Dynamic Watermarking
    Du, Dajun
    Zhang, Changda
    Li, Xue
    Fei, Minrui
    Yang, Taicheng
    Zhou, Huiyu
    [J]. IEEE TRANSACTIONS ON CYBERNETICS, 2022, 52 (12) : 13609 - 13622
  • [10] Fan LX, 2019, ADV NEUR IN, V32