Watermark Removal Scheme Based on Neural Network Model Pruning

被引:1
|
作者
Gu, Wenwen [1 ]
Qian, Haifeng [1 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
来源
2022 5TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND NATURAL LANGUAGE PROCESSING, MLNLP 2022 | 2022年
关键词
Deep neural network; Digital watermarking; Model pruning; Watermark removal;
D O I
10.1145/3578741.3578832
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, due to the rapid development of information technology, machine learning is widely used in various fields. Training deep neural network models is a very expensive process, which requires a lot of training data and hardware resources. Therefore, DNN models can be considered the intellectual property rights of model owners and need to be protected. More and more watermarking algorithms have been studied to embed into neural network models to protect the ownership of the models. At the same time, to test the robustness of the watermark, watermarking attack algorithms have emerged. In this paper, we firstly find the unexpected sensitivity of watermarked models, that is, they are more susceptible to adversarial disturbances than unwatermarked models, and then propose a model repair method based on neural network model pruning. By pruning some sensitive neurons to remove the watermark, the success rate of the watermark can be reduced to a certain extent, and on this basis, it verifies that it can effectively avoid model ownership detection.
引用
收藏
页码:377 / 382
页数:6
相关论文
共 50 条
  • [1] Fused Pruning based Robust Deep Neural Network Watermark Embedding
    Li, Tengfei
    Wang, Shuo
    Jing, Huiyun
    Lian, Zhichao
    Meng, Shunmei
    Li, Qianmu
    2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 2475 - 2481
  • [2] An Incremental Scheme with Weight Pruning to Train Deep Neural Network
    Guo, Haonan
    Yan, Zhicong
    Yang, Jichao
    Li, Shenghong
    COMMUNICATIONS, SIGNAL PROCESSING, AND SYSTEMS, CSPS 2018, VOL III: SYSTEMS, 2020, 517 : 295 - 302
  • [3] Targeted Watermark Removal of a SVD-based Image Watermarking Scheme
    Nikbakht, Pegah
    Mahdavi, Mojtaba
    2015 7th Conference on Information and Knowledge Technology (IKT), 2015,
  • [4] Method of Convolutional Neural Network Model Pruning Based on Gray Correlation Analysis
    Huang Shiqing
    Bai Ruilin
    Qin Gaoe
    LASER & OPTOELECTRONICS PROGRESS, 2020, 57 (04)
  • [5] Visible watermark removal scheme based on reversible data hiding and image inpainting
    Qin, Chuan
    He, Zhihong
    Yao, Heng
    Cao, Fang
    Gao, Liping
    SIGNAL PROCESSING-IMAGE COMMUNICATION, 2018, 60 : 160 - 172
  • [6] FVW: Finding ValuableWeight on Deep Neural Network for Model Pruning
    Zhu, Zhiyu
    Chen, Huaming
    Jin, Zhibo
    Wang, Xinyi
    Zhang, Jiayu
    Xue, Minhui
    Lu, Qinghua
    Shen, Jun
    Choo, Kim-Kwang Raymond
    PROCEEDINGS OF THE 32ND ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2023, 2023, : 3657 - 3666
  • [7] Robust Watermark Algorithm Based on the Wavelet Moment Modulation and Neural Network Detection
    Wang, Dianhong
    Li, Dongming
    Yan, Jun
    ADVANCES IN NEURAL NETWORKS - ISNN 2008, PT 2, PROCEEDINGS, 2008, 5264 : 392 - 401
  • [8] A framework for deep neural network multiuser authorization based on channel pruning
    Wang, Linna
    Song, Yunfei
    Zhu, Yujia
    Xia, Daoxun
    Han, Guoquan
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (21)
  • [9] Blind Watermarking Scheme Based on Neural Network
    Huang, Song
    Zhang, Wei
    Feng, Wei
    Yang, Huaqian
    2008 7TH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION, VOLS 1-23, 2008, : 5985 - +
  • [10] A batch copyright scheme for digital image based on deep neural network
    Lu, Haoyu
    Gong, Daofu
    Liu, Fenlin
    Liu, Hui
    Qu, Jinghua
    MATHEMATICAL BIOSCIENCES AND ENGINEERING, 2019, 16 (05) : 6121 - 6133