paper-with-me

Papers

Evaluating the Robustness of Trigger Set-Based Watermarks Embedded in Deep Neural Networks

2021-06-18 · Suyoung Lee, Wonho Song, Suman Jana, Meeyoung Cha, Sooel Son

Trigger set-based watermarking schemes have gained emerging attention as they provide a means to prove ownership for deep neural network model owners. In this paper, we argue that state-of-the-art trigger set-based watermarking algorithms do not achieve their designed goal of proving ownership. We posit that this impaired capability stems from two common experimental flaws that the existing research practice has committed when evaluating the robustness of watermarking algorithms: (1) incomplete adversarial evaluation and (2) overlooked adaptive attacks. We conduct a comprehensive adversarial evaluation of 11 representative watermarking schemes against six of the existing attacks and demonstrate that each of these watermarking schemes lacks robustness against at least two non-adaptive attacks. We also propose novel adaptive attacks that harness the adversary's knowledge of the underlying watermarking algorithm of a target model. We demonstrate that the proposed attacks effectively break all of the 11 watermarking schemes, consequently allowing adversaries to obscure the ownership of any watermarked model. We encourage follow-up studies to consider our guidelines when evaluating the robustness of their watermarking schemes via conducting comprehensive adversarial evaluation that includes our adaptive attacks to demonstrate a meaningful upper bound of watermark robustness.

📄 PDF Abstract BibTeX arXiv:2106.10147

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Lazy Layers to Make Fine-Tuned Diffusion Models More Traceable

2024-05-01 · Haozhe Liu, Wentian Zhang, Bing Li, Bernard Ghanem 외

Foundational generative models should be traceable to protect their owners and facilitate safety regulation. To achieve this, traditional approaches embed identifiers based on supervisory trigger-response signals, which …

T2S: A Rehearsal-Based Approach for Extraction-Resistant Model Watermarking

2026-06-10 · Jian-Ping Mei, Weibin Zhang, Ao Yao, Tiantian Zhu 외 arxiv

Model watermarking safeguards AI model intellectual property by embedding distinctive knowledge that induces unique behavioral signatures. The primary technical challenge lies in ensuring watermark robustness against var…

Model extraction

Watermarking Pre-trained Language Models with Backdooring

2022-10-14 · Chenxi Gu, Chengsong Huang, Xiaoqing Zheng, Kai-Wei Chang 외

Large pre-trained language models (PLMs) have proven to be a crucial component of modern natural language processing systems. PLMs typically need to be fine-tuned on task-specific downstream datasets, which makes it hard…

Multi-Task Learning

BlockDoor: Blocking Backdoor Based Watermarks in Deep Neural Networks

2024-12-14 · Yi Hao Puah, Anh Tu Ngo, Nandish Chattopadhyay, Anupam Chattopadhyay

Adoption of machine learning models across industries have turned Neural Networks (DNNs) into a prized Intellectual Property (IP), which needs to be protected from being stolen or being used without authorization. This t…

Blocking

On Function-Coupled Watermarks for Deep Neural Networks

2023-02-08 · Xiangyu Wen, Yu Li, Wei Jiang, Qiang Xu

Well-performed deep neural networks (DNNs) generally require massive labelled data and computational resources for training. Various watermarking techniques are proposed to protect such intellectual properties (IPs), whe…

image-classificationImage Classification