Skip to main navigation Skip to search Skip to main content

Nonintrusive Watermarking for CycleGAN

  • Yebin Zheng
  • , Haonan An
  • , Guang Hua*
  • , Yongming Chen
  • , Zhiping Lin
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

Generative adversarial networks (GANs) are a set of powerful generative models, among which CycleGAN, featuring the unique cycle-consistency loss, has gained special popularity. However, this unique structure and the cycle-consistency loss make watermarking CycleGAN particularly challenging, rendering existing deep neural network (DNN) watermarking methods, whether model-agnostic or GAN-specific, inapplicable. Meanwhile, existing DNN watermarking methods are intrusive in nature, requiring direct or indirect modification of model parameters for watermark embedding, which raises fidelity concerns. To solve the above problems, we propose the first nonintrusive and robust watermarking method for CycleGAN. We empirically show that without modifying the CycleGAN model, a user-defined watermark image can still be extracted from model outputs using a dedicated watermark decoder. Extensive experimental results verify that while achieving the so-called absolute fidelity, the proposed method is robust to various attacks, from image post-processing to model stealing.
© 2025 IEEE.
Original languageEnglish
Pages (from-to)256-260
Number of pages5
JournalIEEE Signal Processing Letters
Volume33
Online published12 Dec 2025
DOIs
Publication statusPublished - 2026

Funding

This work was supported by the Singapore Ministry of Education (MOE) through Academic Research Fund (AcRF) Tier 1 under Grant R-MA123-R205-0008.

Research Keywords

  • AI security
  • intellectual property protection
  • nonintrusive watermarking
  • CycleGAN watermarking

Fingerprint

Dive into the research topics of 'Nonintrusive Watermarking for CycleGAN'. Together they form a unique fingerprint.

Cite this