Knowledge-Free Black-Box Watermark and Ownership Proof for Image Classification Neural Networks

04/09/2022
by   Fangqi Li, et al.
0

Watermarking has become a plausible candidate for ownership verification and intellectual property protection of deep neural networks. Regarding image classification neural networks, current watermarking schemes uniformly resort to backdoor triggers. However, injecting a backdoor into a neural network requires knowledge of the training dataset, which is usually unavailable in the real-world commercialization. Meanwhile, established watermarking schemes oversight the potential damage of exposed evidence during ownership verification and the watermarking algorithms themselves. Those concerns decline current watermarking schemes from industrial applications. To confront these challenges, we propose a knowledge-free black-box watermarking scheme for image classification neural networks. The image generator obtained from a data-free distillation process is leveraged to stabilize the network's performance during the backdoor injection. A delicate encoding and verification protocol is designed to ensure the scheme's security against knowledgable adversaries. We also give a pioneering analysis of the capacity of the watermarking scheme. Experiment results proved the functionality-preserving capability and security of the proposed watermarking scheme.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/30/2022

Solving the Capsulation Attack against Backdoor-based Deep Neural Network Watermarks by Reversing Triggers

Backdoor-based watermarking schemes were proposed to protect the intelle...
research
03/18/2021

Secure Watermark for Deep Neural Networks with Multi-task Learning

Deep neural networks are playing an important role in many real-life app...
research
08/20/2021

Regulating Ownership Verification for Deep Neural Networks: Scenarios, Protocols, and Prospects

With the broad application of deep neural networks, the necessity of pro...
research
03/05/2019

DeepStego: Protecting Intellectual Property of Deep Neural Networks by Steganography

Deep Neural Networks (DNNs) has shown great success in various challengi...
research
08/10/2018

Out of the Black Box: Properties of deep neural networks and their applications

Deep neural networks are powerful machine learning approaches that have ...
research
05/08/2022

VPN: Verification of Poisoning in Neural Networks

Neural networks are successfully used in a variety of applications, many...
research
06/22/2022

ROSE: A RObust and SEcure DNN Watermarking

Protecting the Intellectual Property rights of DNN models is of primary ...

Please sign up or login with your details

Forgot password? Click here to reset