Spread-Transform Dither Modulation Watermarking of Deep Neural Network
DNN watermarking is receiving an increasing attention as a suitable mean to protect the Intellectual Property Rights associated to DNN models. Several methods proposed so far are inspired to the popular Spread Spectrum (SS) paradigm according to which the watermark bits are embedded into the projection of the weights of the DNN model onto a pseudorandom sequence. In this paper, we propose a new DNN watermarking algorithm that leverages on the watermarking with side information paradigm to decrease the obtrusiveness of the watermark and increase its payload. In particular, the new scheme exploits the main ideas of ST-DM (Spread Transform Dither Modulation) watermarking to improve the performance of a recently proposed algorithm based on conventional SS. The experiments we carried out by applying the proposed scheme to watermark different models, demonstrate its capability to provide a higher payload with a lower impact on network accuracy than a baseline method based on conventional SS, while retaining a satisfactory level of robustness.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
NSmark: Null Space Based Black-box Watermarking Defense Framework for Language Models
Language models (LMs) have emerged as critical intellectual property (IP) assets that necessitate protection. Although various watermarking strategies have been proposed, they remain vulnerable to Linear Functionality Eq…
Adaptive Dither Voting for Robust Spatial Verification
Hough voting in a geometric transformation space allows us to realize spatial verification, but remains sensitive to feature detection errors because of the inflexible quantization of single feature correspondences. To h…
QuantizationRetrievalSpreading the Wave: Low-Complexity PAPR Reduction for AFDM and OCDM in 6G Networks
High Peak-to-Average Power Ratio (PAPR) is still a common issue in multicarrier signal modulation systems such as Orthogonal Chirp Division Multiplexing (OCDM) and Affine Frequency Division Multiplexing (AFDM), which are…
Zak-OTFS with Spread Carrier Waveforms
Zak-OTFS (orthogonal time frequency space) modulation is a communication framework that parameterizes the wireless channel in the delay-Doppler (DD) domain, where the parameters map directly to physical attributes of the…
Dithering Defense: Adversarial Robustness of Vision Foundation Models via Multi-Level Floyd-Steinberg Dithering
Vision foundation models are widely used as frozen backbones across many downstream tasks, making them a single point of failure under adversarial attack. We study multi-level Floyd-Steinberg error-diffusion dithering as…
Visual Question AnsweringAdversarial RobustnessAdversarial AttackDepth Estimation