Deep Model Intellectual Property Protection via Deep Watermarking

Research output: Journal Publications and Reviews (RGC: 21, 22, 62)21_Publication in refereed journalpeer-review

28 Scopus Citations
View graph of relations

Author(s)

  • Jie Zhang
  • Dongdong Chen
  • Weiming Zhang
  • Huamin Feng
  • Gang Hua
  • Nenghai Yu

Related Research Unit(s)

Detail(s)

Original languageEnglish
Pages (from-to)4005-4020
Journal / PublicationIEEE Transactions on Pattern Analysis and Machine Intelligence
Volume44
Issue number8
Online published9 Mar 2021
Publication statusPublished - 1 Aug 2022

Abstract

Despite the tremendous success, deep neural networks are exposed to serious IP infringement risks. Given a target deep model, if the attacker knows its full information, it can be easily stolen by fine-tuning. Even if only its output is accessible, a surrogate model can be trained through student-teacher learning by generating many input-output training pairs. Therefore, deep model IP protection is important and necessary. However, it is still seriously under-researched. In this work, we propose a new model watermarking framework for protecting deep networks trained for low-level computer vision or image processing tasks. Specifically, a special task-agnostic barrier is added after the target model, which embeds a unified and invisible watermark into its outputs. When the attacker trains one surrogate model by using the input-output pairs of the barrier target model, the hidden watermark will be learned and extracted afterwards. To enable watermarks from binary bits to high-resolution images, a deep invisible watermarking mechanism is designed. By jointly training the target model and watermark embedding, the extra barrier can even be absorbed into the target model. Through extensive experiments, we demonstrate the robustness of the proposed framework, which can resist attacks with different network structures and objective functions.

Research Area(s)

  • Deep Model IP Protection, Image processing, Model Watermarking

Citation Format(s)

Deep Model Intellectual Property Protection via Deep Watermarking. / Zhang, Jie; Chen, Dongdong; Liao, Jing et al.

In: IEEE Transactions on Pattern Analysis and Machine Intelligence, Vol. 44, No. 8, 01.08.2022, p. 4005-4020.

Research output: Journal Publications and Reviews (RGC: 21, 22, 62)21_Publication in refereed journalpeer-review