Abstract
Generative adversarial networks (GANs) are a set of powerful generative models, among which CycleGAN, featuring the unique cycle-consistency loss, has gained special popularity. However, this unique structure and the cycle-consistency loss make watermarking CycleGAN particularly challenging, rendering existing deep neural network (DNN) watermarking methods, whether model-agnostic or GAN-specific, inapplicable. Meanwhile, existing DNN watermarking methods are intrusive in nature, requiring direct or indirect modification of model parameters for watermark embedding, which raises fidelity concerns. To solve the above problems, we propose the first nonintrusive and robust watermarking method for CycleGAN. We empirically show that without modifying the CycleGAN model, a user-defined watermark image can still be extracted from model outputs using a dedicated watermark decoder. Extensive experimental results verify that while achieving the so-called absolute fidelity, the proposed method is robust to various attacks, from image post-processing to model stealing.
© 2025 IEEE.
© 2025 IEEE.
| Original language | English |
|---|---|
| Pages (from-to) | 256-260 |
| Number of pages | 5 |
| Journal | IEEE Signal Processing Letters |
| Volume | 33 |
| Online published | 12 Dec 2025 |
| DOIs | |
| Publication status | Published - 2026 |
Funding
This work was supported by the Singapore Ministry of Education (MOE) through Academic Research Fund (AcRF) Tier 1 under Grant R-MA123-R205-0008.
Research Keywords
- AI security
- intellectual property protection
- nonintrusive watermarking
- CycleGAN watermarking
Fingerprint
Dive into the research topics of 'Nonintrusive Watermarking for CycleGAN'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver