Robust Watermarking for Deep Neural Networks via Bi-level Optimization

被引:29
作者
Yang, Peng [1 ]
Lao, Yingjie [1 ]
Li, Ping [1 ]
机构
[1] Baidu Res, Cognit Comp Lab, 10900 NE 8th St, Bellevue, WA 98004 USA
来源
2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021) | 2021年
关键词
D O I
10.1109/ICCV48922.2021.01457
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks (DNNs) have become state-ofthe-art in many application domains. The increasing complexity and cost for building these models demand means for protecting their intellectual property (IP). This paper presents a novel DNN framework that optimizes the robustness of the embedded watermarks. Our method is originated from DNN fault attacks. Different from prior end-to-end DNN watermarking approaches, we only modify a tiny subset of weights to embed the watermark, which also facilities better control of the model behaviors and enables larger rooms for optimizing the robustness of the watermarks. In this paper, built upon the above concept, we propose a bi-level optimization framework where the inner loop phase optimizes the example-level problem to generate robust exemplars, while the outer loop phase proposes a masked adaptive optimization to achieve the robustness of the projected DNN models. Our method alternates the learning of the protected models and watermark exemplars across all phases, where watermark exemplars are not just data samples that could be optimized and adjusted instead. We verify the performance of the proposed methods over a wide range of datasets and DNN architectures. Various transformation attacks including fine-tuning, pruning and overwriting are used to evaluate the robustness.
引用
收藏
页码:14821 / 14830
页数:10
相关论文
共 32 条
  • [1] Adi Y, 2018, PROCEEDINGS OF THE 27TH USENIX SECURITY SYMPOSIUM, P1615
  • [2] [Anonymous], 2018, P 35 INT C MACH LEAR
  • [3] Athalye A, 2018, PR MACH LEARN RES, V80
  • [4] POSTER: Practical Fault Attack on Deep Neural Networks
    Breier, Jakub
    Hou, Xiaolu
    Jap, Dirmanto
    Ma, Lei
    Bhasin, Shivam
    Liu, Yang
    [J]. PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 2204 - 2206
  • [5] Cao Xiaoyu, 2021, P ACM ASIA C COMP CO
  • [6] Chen H., 2018, ARXIV181103713
  • [7] DeepMarks: A Secure Fingerprinting Framework for Digital Rights Management of Deep Learning Models
    Chen, Huili
    Rouhani, Bita Darvish
    Fu, Cheng
    Zhao, Jishen
    Koushanfar, Farinaz
    [J]. ICMR'19: PROCEEDINGS OF THE 2019 ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA RETRIEVAL, 2019, : 105 - 113
  • [8] Clements J, 2019, IEEE INT SYMP CIRC S
  • [9] Doan Khoa D., 2021, P 2019 IEEE CVF INT
  • [10] Fan Lixin, 2019, Advances in Neural Information Process- ing Systems (NeurIPS), P8