paper-with-me

홈 › Papers

ArmSSL: Adversarial Robust Black-Box Watermarking for Self-Supervised Learning Pre-trained Encoders

2026-04-24 · Yongqi Jiang, Yansong Gao, Boyu Kuang, Chunyi Zhou, Anmin Fu, Liquan Chen arxiv

Self-supervised learning (SSL) encoders are invaluable intellectual property (IP). However, no existing SSL watermarking for IP protection can concurrently satisfy the following two practical requirements: (1) provide ownership verification capability under black-box suspect model access once the stolen encoders are used in downstream tasks; (2) be robust under adversarial watermark detection or removal, because the watermark samples form a distinguishable out-of-distribution (OOD) cluster. We propose ArmSSL, an SSL watermarking framework that assures black-box verifiability and adversarial robustness while preserving utility. For verification, we introduce paired discrepancy enlargement, enforcing feature-space orthogonality between the clean and its watermark counterpart to produce a reliable verification signal in black-box against the suspect model. For adversarial robustness, ArmSSL integrates latent representation entanglement and distribution alignment to suppress the OOD clustering. The former entangles watermark representations with clean representations (i.e., from non-source-class) to avoid forming a dense cluster of watermark samples, while the latter minimizes the distributional discrepancy between watermark and clean representations, thereby disguising watermark samples as natural in-distribution data. For utility, a reference-guided watermark tuning strategy is designed to allow the watermark to be learned as a small side task without affecting the main task by aligning the watermarked encoder's outputs with those of the original clean encoder on normal data. Extensive experiments across five mainstream SSL frameworks and nine benchmark datasets, along with end-to-end comparisons with SOTAs, demonstrate that ArmSSL achieves superior ownership verification, negligible utility degradation, and strong robustness against various adversarial detection and removal.

📄 PDF Abstract BibTeX arXiv:2604.22550

Code (0)

등록된 구현이 없습니다.

Tasks

Self-Supervised LearningAdversarial Robustness

Similar Papers 제목 키워드 기반

Agentic Copyright Watermarking against Adversarial Evidence Forgery with Purification-Agnostic Curriculum Proxy Learning

2024-09-03 · Erjin Bao, Ching-Chun Chang, Hanrui Wang, Isao Echizen

With the proliferation of AI agents in various domains, protecting the ownership of AI models has become crucial due to the significant investment in their development. Unauthorized use and illegal distribution of these …

AWEncoder: Adversarial Watermarking Pre-trained Encoders in Contrastive Learning

2022-08-08 · Tianxing Zhang, Hanzhou Wu, Xiaofeng Lu, Guangling Sun

As a self-supervised learning paradigm, contrastive learning has been widely used to pre-train a powerful encoder as an effective feature extractor for various downstream tasks. This process requires numerous unlabeled t…

Contrastive LearningSelf-Supervised Learning

InvZW: Invariant Feature Learning via Noise-Adversarial Training for Robust Image Zero-Watermarking

2025-06-25 · Abdullah All Tanvir, Xin Zhong

This paper introduces a novel deep learning framework for robust image zero-watermarking based on distortion-invariant feature learning. As a zero-watermarking scheme, our method leaves the original image unaltered and l…

DeMark: A Query-Free Black-Box Attack on Deepfake Watermarking Defenses

2026-01-23 · Wei Song, Zhenchang Xing, Liming Zhu, Yulei Sui 외 arxiv

The rapid proliferation of realistic deepfakes has raised urgent concerns over their misuse, motivating the use of defensive watermarks in synthetic images for reliable detection and provenance tracking. However, this de…

Compressive Sensing

DLOVE: A new Security Evaluation Tool for Deep Learning Based Watermarking Techniques

2024-07-09 · Sudev Kumar Padhi, Sk. Subidh Ali

Recent developments in Deep Neural Network (DNN) based watermarking techniques have shown remarkable performance. The state-of-the-art DNN-based techniques not only surpass the robustness of classical watermarking techni…

Adversarial AttackImage Manipulation