错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Optimized Distribution for Robust Watermarking of Deep Neural Networks Through Fixed Embedding Weights

  • Melisa Çevik,
  • Ege Baran Çakan,
  • Elin Su Şentürk,
  • Utku Anil Çakmak,
  • Marwa Issam Abdulkareem

摘要

This study describes a technique to use watermarking To secure Deep Neural Networks’ (DNNs)’ intellectual property rights. To watermark data, a watermark can be inserted into the trainable parameters of the network, which is known as “white box watermarking”, or into the network’s input-output mapping according to specific inputs (black box watermarking). Watermarking makes it difficult to ensure robustness to network modifications such as fine-tuning, model compression, and transfer learning. The watermark message is encoded in the network’s fixed weights, whose placement is defined by a secret key, for this reason. These weights are set before training and are not modified during it. The spread of watermarked weights is tuned to large amplitudes to increase resilience, while being optimized to be indistinguishable from non-watermarked weights. Experiments show that the proposed approach is able to handle large payloads without significantly affecting the accuracy of the network, and is resistant to various types of network modifications and reuse.