RIGA: Covert and Robust White-Box Watermarking of Deep Neural Networks
arXiv:1910.14268
Abstract
Watermarking of deep neural networks (DNN) can enable their tracing once released by a data owner. In this paper, we generalize white-box watermarking algorithms for DNNs, where the data owner needs white-box access to the model to extract the watermark. White-box watermarking algorithms have the advantage that they do not impact the accuracy of the watermarked model. We propose Robust whIte-box GAn watermarking (RIGA), a novel white-box watermarking algorithm that uses adversarial training. Our extensive experiments demonstrate that the proposed watermarking algorithm not only does not impact accuracy, but also significantly improves the covertness and robustness over the current state-of-art.
WebConf'21 (Full Paper)
References in corpus (6)
- Understanding deep learning requires rethinking generalization
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- DAWN: Dynamic Adversarial Watermarking of Neural Networks
- Piracy Resistant Watermarks for Deep Neural Networks
- Effectiveness of Distillation Attack and Countermeasure on Neural Network Watermarking
- Removing Backdoor-Based Watermarks in Neural Networks with Limited Data
Cited by in corpus (6)
- Intellectual Property Protection for Deep Learning Models: Taxonomy, Methods, Attacks, and Evaluations
- Collecting the Public Perception of AI and Robot Rights
- Secure Watermark for Deep Neural Networks with Multi-task Learning
- Towards Practical Watermark for Deep Neural Networks in Federated Learning
- A survey of deep neural network watermarking techniques
- DPlis: Boosting Utility of Differentially Private Deep Learning via Randomized Smoothing