Backdoor Richer Watermarks Using Dynamic Mask Covering for Dual Identity Verification
摘要
With the increasing prevalence of neural networks, protecting their copyrights has become more critical. Backdoor watermarking serves as a significant method for this purpose. However, existing backdoor watermarks, mainly triggered by visual images, are easily detectable and vulnerable to various attacks such as fine-tuning and compression attacks. They also struggle to convey identity-related information of the creator beyond what the trigger and output sets represent, contributing to their fragility and limitations. In this paper, we propose a novel approach using dynamic masking cover in the image structure as triggers which we named it backdoor richer watermarks. Leveraging the semantic preservation of image structure in transformation attacks, we select image structure as triggers, providing inherent robustness against simple data attacks. We then convert creator-related information into color information to mask-cover the extracted image structure, enabling it to serve as a dual identity verification. Embedding the image structure associated with the creator’s identity as the final trigger pattern, we train the final trigger set alongside clean samples to generate a protected model. Experimental results demonstrate the effectiveness of our proposed approach across different datasets and DNN architectures, offering fidelity, invisibility, robustness and other advantages.