Evolutionary Trigger Set Generation for DNN Black-Box Watermarking
The commercialization of deep learning creates a compelling need for intellectual property (IP) protection. Deep neural network (DNN) watermarking has been proposed as a promising tool to help model owners prove ownership and fight piracy. A popular approach of watermarking is to train a DNN to recognize images with certain \textit{trigger} patterns. In this paper, we propose a novel evolutionary algorithm-based method to generate and optimize trigger patterns. Our method brings a siginificant reduction in false positive rates, leading to compelling proof of ownership. At the same time, it maintains the robustness of the watermark against attacks. We compare our method with the prior art and demonstrate its effectiveness on popular models and datasets.
Code (1)
Similar Papers 제목 키워드 기반
Speech Pattern based Black-box Model Watermarking for Automatic Speech Recognition
As an effective method for intellectual property (IP) protection, model watermarking technology has been applied on a wide variety of deep neural networks (DNN), including speech classification models. However, how to de…
Automatic Speech RecognitionAutomatic Speech Recognition (ASR)Linguistic steganographyspeech-recognition+1On the Robustness of the Backdoor-based Watermarking in Deep Neural Networks
Obtaining the state of the art performance of deep learning models imposes a high cost to model generators, due to the tedious data preparation and the substantial processing requirements. To protect the model from unaut…
Knowledge-Free Black-Box Watermark and Ownership Proof for Image Classification Neural Networks
Watermarking has become a plausible candidate for ownership verification and intellectual property protection of deep neural networks. Regarding image classification neural networks, current watermarking schemes uniforml…
image-classificationImage ClassificationFading the Digital Ink: A Universal Black-Box Attack Framework for 3DGS Watermarking Systems
With the rise of 3D Gaussian Splatting (3DGS), a variety of digital watermarking techniques, embedding either 1D bitstreams or 2D images, are used for copyright protection. However, the robustness of these watermarking t…
Invisible Watermarking for Audio Generation Diffusion Models
Diffusion models have gained prominence in the image domain for their capabilities in data generation and transformation, achieving state-of-the-art performance in various tasks in both image and audio domains. In the ra…
Audio Generation