paper-with-me

Papers

ChainMarks: Securing DNN Watermark with Cryptographic Chain

2025-05-08 · Brian Choi, Shu Wang, Isabelle Choi, Kun Sun

With the widespread deployment of deep neural network (DNN) models, dynamic watermarking techniques are being used to protect the intellectual property of model owners. However, recent studies have shown that existing watermarking schemes are vulnerable to watermark removal and ambiguity attacks. Besides, the vague criteria for determining watermark presence further increase the likelihood of such attacks. In this paper, we propose a secure DNN watermarking scheme named ChainMarks, which generates secure and robust watermarks by introducing a cryptographic chain into the trigger inputs and utilizes a two-phase Monte Carlo method for determining watermark presence. First, ChainMarks generates trigger inputs as a watermark dataset by repeatedly applying a hash function over a secret key, where the target labels associated with trigger inputs are generated from the digital signature of model owner. Then, the watermarked model is produced by training a DNN over both the original and watermark datasets. To verify watermarks, we compare the predicted labels of trigger inputs with the target labels and determine ownership with a more accurate decision threshold that considers the classification probability of specific models. Experimental results show that ChainMarks exhibits higher levels of robustness and security compared to state-of-the-art watermarking schemes. With a better marginal utility, ChainMarks provides a higher probability guarantee of watermark presence in DNN models with the same level of watermark accuracy.

📄 PDF Abstract BibTeX arXiv:2505.04977

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Blind PRNG Hijacking: An Undetectable Integrity-Preserving Attack Against LLM Watermarking

2026-05-27 · Ziyang You, Huilong He, Xiaoke Yang, Xuxing Lu arxiv

Cryptographic watermarking is a leading defense for attributing text generated by large language models (LLMs). Existing schemes, including KGW, Unigram, and DipMark, derive their security guarantees from the assumption …

Deep Learning-based Dual Watermarking for Image Copyright Protection and Authentication

2025-02-21 · Sudev Kumar Padhi, Archana Tiwari, Sk. Subidh Ali

Advancements in digital technologies make it easy to modify the content of digital images. Hence, ensuring digital images integrity and authenticity is necessary to protect them against various attacks that manipulate th…

SSIM

Towards A Correct Usage of Cryptography in Semantic Watermarks for Diffusion Models

2025-03-14 · Jonas Thietke, Andreas Müller, Denis Lukovnikov, Asja Fischer 외

Semantic watermarking methods enable the direct integration of watermarks into the generation process of latent diffusion models by only modifying the initial latent noise. One line of approaches building on Gaussian Sha…

Management

MetaSeal: Defending Against Image Attribution Forgery Through Content-Dependent Cryptographic Watermarks

2025-09-13 · Tong Zhou, Ruyi Ding, Gaowen Liu, Charles Fleming 외 arxiv

The rapid growth of digital and AI-generated images has amplified the need for secure and verifiable methods of image attribution. While digital watermarking offers more robust protection than metadata-based approaches--…

Image Attribution

Authenticated Contradictions from Desynchronized Provenance and Watermarking

2026-03-02 · Alexander Nemecek, Hengzhi He, Guang Cheng, Erman Ayday arxiv

Cryptographic provenance standards such as C2PA and invisible watermarking are positioned as complementary defenses for content authentication, yet the two verification layers are technically independent: neither conditi…