Black-Box Watermarking and Blockchain for IP Protection of Voiceprint Recognition Model

被引:4
作者
Zhang, Jing [1 ]
Dai, Long [1 ]
Xu, Liaoran [1 ]
Ma, Jixin [2 ]
Zhou, Xiaoyi [1 ]
机构
[1] Hainan Univ, Sch Cyberspace Secur, Haikou 570228, Peoples R China
[2] Univ Greenwich, Fac Engn & Sci, Sch Comp & Math Sci, London SE10 9LS, England
关键词
copyright protection; voiceprint recognition model; watermarking; blockchain; black-box; Mel spectrogram;
D O I
10.3390/electronics12173697
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep neural networks are widely used for voiceprint recognition, whilst voiceprint recognition models are vulnerable to attacks. Existing protection schemes for voiceprint recognition models are insufficient to withstand various robustness attacks and cannot prevent model theft. This paper proposes a black-box voiceprint recognition model protection framework that combines active and passive protection. It embeds key information into the Mel spectrogram to generate trigger samples that are difficult to detect and remove and injects them into the host model as watermark W, thereby enhancing the copyright protection performance of the voiceprint recognition model. To restrict the use of the model by unauthorized users, the index number corresponding to the model and the encrypted model information are stored on the blockchain, and then, an exclusive smart contract is designed to restrict access to the model. Experimental results show that this framework effectively protects voiceprint recognition model copyrights and restricts unauthorized access.
引用
收藏
页数:16
相关论文
共 50 条
[1]  
Adi Y, 2018, PROCEEDINGS OF THE 27TH USENIX SECURITY SYMPOSIUM, P1615
[2]  
Amodei D, 2016, PR MACH LEARN RES, V48
[3]  
[Anonymous], TIMIT acoustic phonetic continuous speech corpus
[4]   SpecMark: A Spectral Watermarking Framework for IP Protection of Speech Recognition Systems [J].
Chen, Huili ;
Darvish, Bita ;
Koushanfar, Farinaz .
INTERSPEECH 2020, 2020, :2312-2316
[5]  
Chen JL, 2022, P IEEE S SECUR PRIV, P824, DOI [10.1109/SP46214.2022.9833747, 10.1109/SP46214.2022.00059]
[6]  
Chen X., 2019, P ICML WORKSH SEC PR, P1
[7]   Image Watermarking Using Least Significant Bit and Canny Edge Detection [J].
Faheem, Zaid Bin ;
Ishaq, Abid ;
Rustam, Furqan ;
de la Torre Diez, Isabel ;
Gavilanes, Daniel ;
Vergara, Manuel Masias ;
Ashraf, Imran .
SENSORS, 2023, 23 (03)
[8]  
Fan L., 2019, P 33 C NEURAL INFORM, P1
[9]  
Fan XF, 2023, Arxiv, DOI arXiv:2206.02541
[10]  
[樊雪峰 Fan Xuefeng], 2022, [计算机研究与发展, Journal of Computer Research and Development], V59, P953