Deakin University
Browse

File(s) under permanent embargo

Protecting the intellectual property of deep neural networks with watermarking: The frequency domain approach

Version 2 2024-06-06, 06:33
Version 1 2021-03-04, 15:04
conference contribution
posted on 2024-06-06, 06:33 authored by M Li, Q Zhong, Leo ZhangLeo Zhang, Y Du, Jun Zhang, Yong XiangYong Xiang
Similar to other digital assets, deep neural network (DNN) models could suffer from piracy threat initiated by insider and/or outsider adversaries due to their inherent commercial value. DNN watermarking is a promising technique to mitigate this threat to intellectual property. This work focuses on black-box DNN watermarking, with which an owner can only verify his ownership by issuing special trigger queries to a remote suspicious model. However, informed attackers, who are aware of the watermark and somehow obtain the triggers, could forge fake triggers to claim their ownerships since the poor robustness of triggers and the lack of correlation between the model and the owner identity. This consideration calls for new watermarking methods that can achieve better trade-off for addressing the discrepancy. In this paper, we exploit frequency domain image watermarking to generate triggers and build ourDNN watermarking algorithm accordingly. Since watermarking in the frequency domain is high concealment and robust to signal processing operation, the proposed algorithm is superior to existing schemes in resisting fraudulent claim attack. Besides, ex-tensive experimental results on3datasets and8neural networks demonstrate that the proposed DNN watermarking algorithm achieves similar performance on functionality metrics and better performance on security metrics when compared with existing algorithms

History

Pagination

402-409

Location

Guangzhou, China (part-virtually)

Start date

2020-12-29

End date

2021-01-01

ISSN

2324-898X

eISSN

2324-9013

ISBN-13

9780738143804

Language

eng

Notes

DOI Not Found : Error https://doi.org/10.1109/TrustCom50675.2020.00062

Publication classification

E1 Full written paper - refereed

Copyright notice

2020, Institute of Electrical and Electronics Engineers

Editor/Contributor(s)

Wang G, Ko R, Alam Bhuiyan MZ, Pan Y

Title of proceedings

TrustCom 2020 : Proceedings of IEEE's 19th International Conference on Trust, Security and Privacy in Computing and Communications

Event

TrustCom 2020. Trust, Security and Privacy in Computing and Communications. IEEE International Conference (19th : 2020 : Guangzhou, China)

Publisher

IEEE Computer Society

Place of publication

Los Alamitos, Calif.