Copyright protection of deep image classification models

被引:0
作者
Vybornova, Y. D. [1 ]
Ulyanov, D. I. [1 ]
机构
[1] Samara Natl Res Univ, Moskovskoye Shosse 34, Samara 443086, Russia
基金
俄罗斯科学基金会;
关键词
image classification models; digital watermarking; copyright protection; pseudoholographic images; WATERMARKING;
D O I
10.18287/2412-6179-CO-1302
中图分类号
O43 [光学];
学科分类号
070207 ; 0803 ;
摘要
With the growing number of tasks solved using deep learning methods, the need for protection against unauthorized distribution of the intellectual property such as pre-trained models of deep neural networks is growing. To date, one of the most common ways to protect copyright in the digital space is through embedding digital watermarks. When solving the problem of watermark embedding, an important criterion is the preservation of the model prediction accuracy after intro-ducing the protective information. In this paper, we propose a method for embedding digital wa-termarks into image classification models based on adding images obtained by superimposing pseudo-holograms on images of the original dataset to the training set. A pseudo-hologram is an image synthesized on the basis of a given binary sequence by arranging pulses for bit encoding in the spectral region. Results of the experimental study show that the proposed method allows one to maintain the classification quality, while also retaining its performance regardless of the architec-ture of the protected neural network. The conducted series of attacks on protected models show that attempts of an attacker to completely remove the watermark will almost inevitably lead to a significant loss in the model prediction quality. The results of the experiments also include rec-ommendations on the choice of method parameters, such as the size of the trigger and training sets, as well as the length of sequences encoded by pseudo-holograms.
引用
收藏
页码:980 / +
页数:12
相关论文
共 24 条
  • [1] [Anonymous], 2023, Cifar-10 dataset
  • [2] Digital Image Watermarking Using Least Significant Bit Technique in Different Bit Positions
    Bansal, Neha
    Deolia, Vinay Kumar
    Bansal, Atul
    Pathak, Pooja
    [J]. 2014 6TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS, 2014, : 813 - 818
  • [3] A Systematic Review on Model Watermarking for Neural Networks
    Boenisch, Franziska
    [J]. FRONTIERS IN BIG DATA, 2021, 4
  • [4] NeuNAC: A novel fragile watermarking algorithm for integrity protection of neural networks
    Botta, Marco
    Cavagnino, Davide
    Esposito, Roberto
    [J]. INFORMATION SCIENCES, 2021, 576 : 228 - 241
  • [5] Deeba Farah, 2020, International Journal of Machine Learning and Computing, P277, DOI 10.18178/ijmlc.2020.10.2.932
  • [6] A Novel Watermarking Mechanism for Deep Learning Models rased on Chaotic Boundaries
    Huang, Zi-Jie
    Zhang, Ying-Qian
    Jia, Yi-Ran
    [J]. 2021 15TH INTERNATIONAL SYMPOSIUM ON MEDICAL INFORMATION AND COMMUNICATION TECHNOLOGY (ISMICT), 2021, : 104 - 109
  • [7] KeyNet: An Asymmetric Key-Style Framework for Watermarking Deep Learning Models
    Jebreel, Najeeb Moharram
    Domingo-Ferrer, Josep
    Sanchez, David
    Blanco-Justicia, Alberto
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (03): : 1 - 22
  • [8] A Protocol for Secure Verification ofWatermarks Embedded into Machine Learning Models
    Kapusta, Katarzyna
    Thouvenot, Vincent
    Bettan, Olivier
    Beguinet, Hugo
    Senet, Hugo
    [J]. PROCEEDINGS OF THE 2021 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH&MMSEC 2021, 2021, : 171 - 176
  • [9] White-BoxWatermarking Scheme for Fully-Connected Layers in Fine-Tuning Model
    Kuribayashi, Minoru
    Tanaka, Takuro
    Suzuki, Shunta
    Yasui, Tatsuya
    Funabiki, Nobuo
    [J]. PROCEEDINGS OF THE 2021 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH&MMSEC 2021, 2021, : 165 - 170
  • [10] A survey of Deep Neural Network watermarking techniques
    Li, Yue
    Wang, Hongxia
    Barni, Mauro
    [J]. NEUROCOMPUTING, 2021, 461 : 171 - 193