Skip to main navigation Skip to search Skip to main content

Protecting Image Processing Networks via Model Watermarking

  • Jie Zhang*
  • , Dongdong Chen
  • , Jing Liao
  • , Weiming Zhang
  • , Nenghai Yu
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 12 - Chapter in an edited book (Author)peer-review

Abstract

Deep learning has achieved tremendous success in low-level computer vision tasks such as image processing tasks. To protect the intellectual property (IP) of such valuable image processing networks, the model vendor can sell the service in the manner of the application program interface (API). However, even if the attacker can only query the API, he is still able to conduct model extraction attacks, which can steal the functionality of the target networks. In this chapter, we propose a new model watermarking framework for image processing networks. Under the framework, two strategies are further developed, namely, the model-agnostic strategy and the model-specific strategy. The proposed watermarking method performs well in terms of fidelity, capacity, and robustness. © The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2023
Original languageEnglish
Title of host publicationDigital Watermarking for Machine Learning Model
Subtitle of host publicationTechniques, Protocols and Applications
EditorsLixin Fan, Chee Seng Chan, Qiang Yang
Place of PublicationSingapore
PublisherSpringer 
Chapter6
Pages93–116
ISBN (Electronic)978-981-19-7554-7
ISBN (Print)978-981-19-7553-0
DOIs
Publication statusPublished - 2023

Bibliographical note

Research Unit(s) information for this publication is provided by the author(s) concerned.

Funding

This research was partly supported by the Natural Science Foundation of China under Grant U20B2047, 62072421, 62002334, 62102386, and 62121002, Exploration Fund Project of University of Science and Technology of China under Grant YD3480002001.

Fingerprint

Dive into the research topics of 'Protecting Image Processing Networks via Model Watermarking'. Together they form a unique fingerprint.

Cite this