Deep Model Intellectual Property Protection via Deep Watermarking

被引:86
作者
Zhang, Jie [1 ]
Chen, Dongdong [2 ]
Liao, Jing [3 ]
Zhang, Weiming [1 ]
Feng, Huamin [4 ]
Hua, Gang [5 ]
Yu, Nenghai [1 ]
机构
[1] Univ Sci & Technol China, Sch Cyber Sci & Secur, Hefei 230026, Anhui, Peoples R China
[2] Microsoft Res, Redmond, WA 98052 USA
[3] City Univ Hong Kong, Dept Comp Sci, Kowloon Tong, Hong Kong, Peoples R China
[4] Beijing Elect Sci & Technol Inst, Beijing 100070, Peoples R China
[5] Wormpex AI Res LLC, Bellevue, WA 98004 USA
基金
国家重点研发计划;
关键词
Watermarking; Computational modeling; Training; Task analysis; IP networks; Image processing; Media; Deep model IP protection; model watermarking; image processing; COPYRIGHT PROTECTION; IMAGES; ROBUST; NETWORKS; SCHEME;
D O I
10.1109/TPAMI.2021.3064850
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Despite the tremendous success, deep neural networks are exposed to serious IP infringement risks. Given a target deep model, if the attacker knows its full information, it can be easily stolen by fine-tuning. Even if only its output is accessible, a surrogate model can be trained through student-teacher learning by generating many input-output training pairs. Therefore, deep model IP protection is important and necessary. However, it is still seriously under-researched. In this work, we propose a new model watermarking framework for protecting deep networks trained for low-level computer vision or image processing tasks. Specifically, a special task-agnostic barrier is added after the target model, which embeds a unified and invisible watermark into its outputs. When the attacker trains one surrogate model by using the input-output pairs of the barrier target model, the hidden watermark will be learned and extracted afterwards. To enable watermarks from binary bits to high-resolution images, a deep invisible watermarking mechanism is designed. By jointly training the target model and watermark embedding, the extra barrier can even be absorbed into the target model. Through extensive experiments, we demonstrate the robustness of the proposed framework, which can resist attacks with different network structures and objective functions.
引用
收藏
页码:4005 / 4020
页数:16
相关论文
共 68 条
[1]  
Adi Y, 2018, PROCEEDINGS OF THE 27TH USENIX SECURITY SYMPOSIUM, P1615
[2]  
[Anonymous], 2018, INT J MULTIMEDIA INF
[3]  
Ba LJ, 2014, ADV NEUR IN, V27
[4]   Improved wavelet-based watermarking through pixel-wise masking [J].
Barni, M ;
Bartolini, F ;
Piva, A .
IEEE TRANSACTIONS ON IMAGE PROCESSING, 2001, 10 (05) :783-791
[5]   Controllable Image Processing via Adaptive FilterBank Pyramid [J].
Chen, Dongdong ;
Fan, Qingnan ;
Liao, Jing ;
Aviles-Rivero, Angelica ;
Yuan, Lu ;
Yu, Nenghai ;
Hua, Gang .
IEEE TRANSACTIONS ON IMAGE PROCESSING, 2020, 29 :8043-8054
[6]   Explicit Filterbank Learning for Neural Image Style Transfer and Image Processing [J].
Chen, Dongdong ;
Yuan, Lu ;
Liao, Jing ;
Yu, Nenghai ;
Hua, Gang .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2021, 43 (07) :2373-2387
[7]   Gated Context Aggregation Network for Image Dehazing and Deraining [J].
Chen, Dongdong ;
He, Mingming ;
Fan, Qingnan ;
Liao, Jing ;
Zhang, Liheng ;
Hou, Dongdong ;
Yuan, Lu ;
Hua, Gang .
2019 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2019, :1375-1383
[8]   Coherent Online Video Style Transfer [J].
Chen, Dongdong ;
Liao, Jing ;
Yuan, Lu ;
Yu, Nenghai ;
Hua, Gang .
2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2017, :1114-1123
[9]   StyleBank: An Explicit Representation for Neural Image Style Transfer [J].
Chen, Dongdong ;
Yuan, Lu ;
Liao, Jing ;
Yu, Nenghai ;
Hua, Gang .
30TH IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2017), 2017, :2770-2779
[10]  
Chen H., 2019, ARXIV 190400344