paper-with-me

홈 › Papers

Wide Flat Minimum Watermarking for Robust Ownership Verification of GANs

2023-10-25 · Jianwei Fei, Zhihua Xia, Benedetta Tondi, Mauro Barni

We propose a novel multi-bit box-free watermarking method for the protection of Intellectual Property Rights (IPR) of GANs with improved robustness against white-box attacks like fine-tuning, pruning, quantization, and surrogate model attacks. The watermark is embedded by adding an extra watermarking loss term during GAN training, ensuring that the images generated by the GAN contain an invisible watermark that can be retrieved by a pre-trained watermark decoder. In order to improve the robustness against white-box model-level attacks, we make sure that the model converges to a wide flat minimum of the watermarking loss term, in such a way that any modification of the model parameters does not erase the watermark. To do so, we add random noise vectors to the parameters of the generator and require that the watermarking loss term is as invariant as possible with respect to the presence of noise. This procedure forces the generator to converge to a wide flat minimum of the watermarking loss. The proposed method is architectureand dataset-agnostic, thus being applicable to many different generation tasks and models, as well as to CNN-based image processing architectures. We present the results of extensive experiments showing that the presence of the watermark has a negligible impact on the quality of the generated images, and proving the superior robustness of the watermark against model modification and surrogate model attacks.

📄 PDF Abstract BibTeX arXiv:2310.16919

Code (0)

등록된 구현이 없습니다.

Tasks

Quantization

Similar Papers 제목 키워드 기반

Knowledge-Free Black-Box Watermark and Ownership Proof for Image Classification Neural Networks

2022-04-09 · Fangqi Li, Shilin Wang

Watermarking has become a plausible candidate for ownership verification and intellectual property protection of deep neural networks. Regarding image classification neural networks, current watermarking schemes uniforml…

image-classificationImage Classification

On the Effectiveness of Dataset Watermarking in Adversarial Settings

2022-02-25 · Buse Gul Atli Tekgul, N. Asokan

In a data-driven world, datasets constitute a significant economic value. Dataset owners who spend time and money to collect and curate the data are incentivized to ensure that their datasets are not used in ways that th…

Model extraction

FLClear: Visually Verifiable Multi-Client Watermarking for Federated Learning

2025-11-16 · Chen Gu, Yingying Sun, Yifan She, Donghui Hu arxiv

Federated learning (FL) enables multiple clients to collaboratively train a shared global model while preserving the privacy of their local data. Within this paradigm, the intellectual property rights (IPR) of client mod…

Contrastive LearningFederated Learning

CBW: Towards Dataset Ownership Verification for Speaker Verification via Clustering-based Backdoor Watermarking

2025-03-02 · Yiming Li, Kaiying Yan, Shuo Shao, Tongqing Zhai 외

With the increasing adoption of deep learning in speaker verification, large-scale speech datasets have become valuable intellectual property. To audit and prevent the unauthorized usage of these valuable released datase…

Speaker Verification

Black-box Dataset Ownership Verification via Backdoor Watermarking

2022-08-04 · Yiming Li, Mingyan Zhu, Xue Yang, Yong Jiang 외

Deep learning, especially deep neural networks (DNNs), has been widely and successfully adopted in many critical applications for its high effectiveness and efficiency. The rapid development of DNNs has benefited from th…