A spatiotemporal chaos based deep learning model watermarking scheme

被引:2
作者
Wang, Dehui [1 ]
Zhou, Shuang [2 ]
Zhang, Yingqian [3 ,4 ]
机构
[1] Beihang Univ, Sch Math Sci, Beijing 100000, Peoples R China
[2] Chongqing Normal Univ, Sch Math Sci, Chongqing 401331, Peoples R China
[3] Xiamen Univ, Tan Kah Kee Coll, Sch Informat Sci & Technol, Zhangzhou 363105, Peoples R China
[4] Xiamen Univ Malaysia, Sch EEAI, Sepang 43900, Selangor, Malaysia
基金
中国国家自然科学基金;
关键词
Deep learning; Spatiotemporal chaos; Watermarking; Intellectual property protection; Chaotic annotation;
D O I
10.1016/j.asoc.2024.112004
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With deep learning techniques achieving great results in modern industry, the intellectual property (IP) protection for deep learning models has attracted the attention of academics and engineers. However, training a commercially viable deep learning model usually needs professional resources and time. Once a malicious user clones, illegally distributes and uses the model, it can infringe on the model owner's IP and even steal its market share. Among the existing IP protection methods, scholars prefer the black-box watermarking approaches, of which the content of the trigger set and the label are the key part of the watermarking technique. However, most schemes do not consider the security and invisibility of the trigger set, which allows attackers to easily trigger the model by creating a fake trigger set, thereby committing a fraudulent ownership claim attack and claiming the ownership belongs to themselves. To overcome these drawbacks, we proposed a spatiotemporal chaotic data annotation method. Firstly, the unpredictability and acyclicity of chaos make the model resistant to fraudulent ownership claim attacks, statistical inference and other common machine learning attacks; Secondly, the trigger set and parameters are independent of each other, guaranteeing the security of the key; Thirdly, the spatiotemporal chaotic system provides a large key space, which meets the commercialization needs of deep learning models. Theoretical analysis and experimental results show that our scheme has security, practicality and robustness. To further validate the superiority of the proposed method, we also compare it with the Logistic chaotic annotation watermarking-based method, and the results show that our method performs better in terms of robustness, effectiveness, completeness, fidelity, security and practicality.
引用
收藏
页数:17
相关论文
共 50 条
  • [11] Watermarking Deep Neural Networks for Embedded Systems
    Guo, Jia
    Potkonjak, Miodrag
    [J]. 2018 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD) DIGEST OF TECHNICAL PAPERS, 2018,
  • [12] Deep Residual Learning for Image Recognition
    He, Kaiming
    Zhang, Xiangyu
    Ren, Shaoqing
    Sun, Jian
    [J]. 2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, : 770 - 778
  • [13] Hitaj D, 2018, Arxiv, DOI arXiv:1809.00615
  • [14] Unambiguous and High-Fidelity Backdoor Watermarking for Deep Neural Networks
    Hua, Guang
    Teoh, Andrew Beng Jin
    Xiang, Yong
    Jiang, Hao
    [J]. IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (08) : 11204 - 11217
  • [15] Two-Dimensional Parametric Polynomial Chaotic System
    Hua, Zhongyun
    Chen, Yongyong
    Bao, Han
    Zhou, Yicong
    [J]. IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2022, 52 (07): : 4402 - 4414
  • [16] Renewable sources-based automatic load frequency control of interconnected systems using chaotic atom search optimization
    Irudayaraj, Andrew Xavier Raj
    Wahab, Noor Izzri Abdul
    Premkumar, Manoharan A.
    Radzi, Mohd Amran Mohd
    Sulaiman, Nasri Bin
    Veerasamy, Veerapandiyan
    Farade, Rizwan A.
    Islam, Mohammad Zohrul
    [J]. APPLIED SOFT COMPUTING, 2022, 119
  • [17] KeyNet: An Asymmetric Key-Style Framework for Watermarking Deep Learning Models
    Jebreel, Najeeb Moharram
    Domingo-Ferrer, Josep
    Sanchez, David
    Blanco-Justicia, Alberto
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (03): : 1 - 22
  • [18] Robust color image watermarking algorithm based on synchronization correction with multi-layer perceptron and Cauchy distribution model
    Jiang, Mei-ru
    Feng, Xiu-fang
    Wang, Chun-peng
    Fan, Xiao-le
    Zhang, Hao
    [J]. APPLIED SOFT COMPUTING, 2023, 140
  • [19] ImageNet Classification with Deep Convolutional Neural Networks
    Krizhevsky, Alex
    Sutskever, Ilya
    Hinton, Geoffrey E.
    [J]. COMMUNICATIONS OF THE ACM, 2017, 60 (06) : 84 - 90
  • [20] Adversarial frontier stitching for remote neural network watermarking
    Le Merrer, Erwan
    Perez, Patrick
    Tredan, Gilles
    [J]. NEURAL COMPUTING & APPLICATIONS, 2020, 32 (13) : 9233 - 9244