Robust Watermarking for Neural Network Models Using Residual Network

被引:1
作者
Wang, Lecong [1 ]
Wang, Zichi [2 ]
Li, Xinran [1 ]
Qin, Chuan [1 ]
机构
[1] Univ Shanghai Sci & Technol, Sch Opt Elect & Comp Engn, Shanghai, Peoples R China
[2] Shanghai Univ, Sch Commun & Informat Engn, Shanghai, Peoples R China
来源
2022 IEEE 24TH INTERNATIONAL WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING (MMSP) | 2022年
基金
上海市自然科学基金; 中国国家自然科学基金;
关键词
Digital watermarking; robustness; neural networks; residual block;
D O I
10.1109/MMSP55362.2022.9949601
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The training process of a neural network model requires plenty of costs, and so the intellectual property of neural network models should be protected. To this end, we propose a robust watermarking scheme for neural network models in this paper. In our scheme, an independent network is specially designed to help embedding watermarks into a given host network, and also be used for watermark extraction. The independent network is designed based on the residual structure which is sensitive to the parameter changes of the host network and conducive to finding suitable embedding locations. In addition, some residual blocks are randomly discarded during watermark embedding, which can increase the robustness against popular model attacks. Experimental results show that our scheme achieves satisfactory watermark verification performance without decreasing the original performance of the host network, even if the host network has been maliciously tampered.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Identification and control of the AWS using neural network models
    Valerio, Duarte
    Mendes, Mario J. G. C.
    Beirao, Pedro
    da Costa, Jose Sa
    APPLIED OCEAN RESEARCH, 2008, 30 (03) : 178 - 188
  • [32] Digital Watermarking Based on Neural Network and Image Features
    Huang, Song
    Zhang, Wei
    ICIC 2009: SECOND INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTING SCIENCE, VOL 2, PROCEEDINGS: IMAGE ANALYSIS, INFORMATION AND SIGNAL PROCESSING, 2009, : 238 - +
  • [33] A convolutional neural network-based blind robust image watermarking approach exploiting the frequency domain
    Zhiwei Zhang
    Han Wang
    Hui Fu
    The Visual Computer, 2023, 39 : 3533 - 3544
  • [34] Applications of a neural network to watermarking capacity of digital image
    Zhang, F
    Zhang, HB
    NEUROCOMPUTING, 2005, 67 : 345 - 349
  • [35] A convolutional neural network-based blind robust image watermarking approach exploiting the frequency domain
    Zhang, Zhiwei
    Wang, Han
    Fu, Hui
    VISUAL COMPUTER, 2023, 39 (08) : 3533 - 3544
  • [36] Robust Neural Network for Wavefront Reconstruction Using Zernike Coefficients
    Ambrose, Adrian
    Dillon, Keith
    APPLICATIONS OF MACHINE LEARNING 2020, 2020, 11511
  • [37] ROWBACK: RObust Watermarking for neural networks using BACKdoors
    Chattopadhyay, Nandish
    Chattopadhyay, Anupam
    20TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA 2021), 2021, : 1728 - 1735
  • [38] On making neural network based learning systems robust
    Ghosh, A
    Tanaka, H
    IETE JOURNAL OF RESEARCH, 1998, 44 (4-5) : 219 - 225
  • [39] Robust Fuzzy Neural Network With an Adaptive Inference Engine
    Zhang, Leijie
    Shi, Ye
    Chang, Yu-Cheng
    Lin, Chin-Teng
    IEEE TRANSACTIONS ON CYBERNETICS, 2024, 54 (05) : 3275 - 3285
  • [40] Using measured damage parameters to predict the residual strength of impacted composites: A neural network approach
    Highsmith, AL
    Keshav, S
    JOURNAL OF COMPOSITES TECHNOLOGY & RESEARCH, 1997, 19 (04): : 195 - 201