Intellectual Property Protection of Image Processing Models with Watermarking
摘要
In recent years, deep learning has achieved remarkable success in many fields. But training an effective model is often costly, so deep learning models are valuable. At the same time, the increasingly wide deployment and sharing of models may pose the risk of model theft. There is a serious concern: how to protect the intellectual property of the models owners and verify the ownership of the models when these models are stolen by some attackers. The emergence of model watermarking provides a way to protect the IP of deep learning models owners. However, there is a lack of research on watermarking of image processing models and existing methods can not be transfered directly to image processing model. In this paper, a novel watermarking method is proposed for protecting image processing models in the black-box scenario. We use watermarked training data to watermark the target model while training it. The proposed method can verify ownership of the model in the black-box scenario and has robustness and resistance to common model attacks.