English

Piracy-Resistant DNN Watermarking by Block-Wise Image Transformation with Secret Key

Computer Vision and Pattern Recognition 2021-04-12 v1 Cryptography and Security Image and Video Processing

Abstract

In this paper, we propose a novel DNN watermarking method that utilizes a learnable image transformation method with a secret key. The proposed method embeds a watermark pattern in a model by using learnable transformed images and allows us to remotely verify the ownership of the model. As a result, it is piracy-resistant, so the original watermark cannot be overwritten by a pirated watermark, and adding a new watermark decreases the model accuracy unlike most of the existing DNN watermarking methods. In addition, it does not require a special pre-defined training set or trigger set. We empirically evaluated the proposed method on the CIFAR-10 dataset. The results show that it was resilient against fine-tuning and pruning attacks while maintaining a high watermark-detection accuracy.

Keywords

Cite

@article{arxiv.2104.04241,
  title  = {Piracy-Resistant DNN Watermarking by Block-Wise Image Transformation with Secret Key},
  author = {MaungMaung AprilPyone and Hitoshi Kiya},
  journal= {arXiv preprint arXiv:2104.04241},
  year   = {2021}
}