English
Related papers

Related papers: Removing Backdoor-Based Watermarks in Neural Netwo…

200 papers

In order to protect the intellectual property (IP) of deep neural networks (DNNs), many existing DNN watermarking techniques either embed watermarks directly into the DNN parameters or insert backdoor watermarks by fine-tuning the DNN…

Cryptography and Security · Computer Science 2021-10-19 Xiangyu Zhao , Yinzhe Yao , Hanzhou Wu , Xinpeng Zhang

Visible watermark removal which involves watermark cleaning and background content restoration is pivotal to evaluate the resilience of watermarks. Existing deep neural network (DNN)-based models still struggle with large-area watermarks…

Computer Vision and Pattern Recognition · Computer Science 2025-04-08 Yicheng Leng , Chaowei Fang , Junye Chen , Yixiang Fang , Sheng Li , Guanbin Li

The intellectual property of deep neural network (DNN) models can be protected with DNN watermarking, which embeds copyright watermarks into model parameters (white-box), model behavior (black-box), or model outputs (box-free), and the…

Cryptography and Security · Computer Science 2025-07-25 Haonan An , Guang Hua , Yu Guo , Hangcheng Cao , Susanto Rahardja , Yuguang Fang

As a valuable digital product, deep neural networks (DNNs) face increasingly severe threats to the intellectual property, making it necessary to develop effective technical measures to protect them. Trigger-based watermarking methods…

Cryptography and Security · Computer Science 2025-10-27 Chaoyue Huang , Gejian Zhao , Hanzhou Wu , Zhihua Xia , Asad Malik

Out-of-distribution (OOD) detection aims to identify OOD data based on representations extracted from well-trained deep models. However, existing methods largely ignore the reprogramming property of deep models and thus may not fully…

Machine Learning · Computer Science 2022-10-28 Qizhou Wang , Feng Liu , Yonggang Zhang , Jing Zhang , Chen Gong , Tongliang Liu , Bo Han

Despite the tremendous success, deep neural networks are exposed to serious IP infringement risks. Given a target deep model, if the attacker knows its full information, it can be easily stolen by fine-tuning. Even if only its output is…

Computer Vision and Pattern Recognition · Computer Science 2021-03-09 Jie Zhang , Dongdong Chen , Jing Liao , Weiming Zhang , Huamin Feng , Gang Hua , Nenghai Yu

Triggerable watermarking enables model owners to assert ownership against model extraction attacks. However, most existing approaches require additional training, which limits post-deployment flexibility, and the lack of clear theoretical…

Cryptography and Security · Computer Science 2026-01-22 Yixiao Xu , Binxing Fang , Rui Wang , Yinghai Zhou , Yuan Liu , Mohan Li , Zhihong Tian

Backdoor attack aims to deceive a victim model when facing backdoor instances while maintaining its performance on benign data. Current methods use manual patterns or special perturbations as triggers, while they often overlook the…

Computer Vision and Pattern Recognition · Computer Science 2024-01-05 Ruofei Wang , Renjie Wan , Zongyu Guo , Qing Guo , Rui Huang

With the advancement of intelligent healthcare, medical pre-trained language models (Med-PLMs) have emerged and demonstrated significant effectiveness in downstream medical tasks. While these models are valuable assets, they are vulnerable…

Machine Learning · Computer Science 2025-04-16 Cong Kong , Rui Xu , Weixi Chen , Jiawei Chen , Zhaoxia Yin

Technologies of the Internet of Things (IoT) facilitate digital contents such as images being acquired in a massive way. However, consideration from the privacy or legislation perspective still demands the need for intellectual content…

Multimedia · Computer Science 2020-03-30 Yurui Ming , Weiping Ding , Zehong Cao , Chin-Teng Lin

Visible watermarks are widely-used in images to protect copyright ownership. Analyzing watermark removal helps to reinforce the anti-attack techniques in an adversarial way. Current removal methods normally leverage image-to-image…

Computer Vision and Pattern Recognition · Computer Science 2020-12-16 Yang Liu , Zhen Zhu , Xiang Bai

As deep learning (DL) models are widely and effectively used in Machine Learning as a Service (MLaaS) platforms, there is a rapidly growing interest in DL watermarking techniques that can be used to confirm the ownership of a particular…

Cryptography and Security · Computer Science 2024-11-22 Mikhail Pautov , Nikita Bogdanov , Stanislav Pyatkin , Oleg Rogov , Ivan Oseledets

Watermarking techniques are vital for protecting intellectual property and preventing fraudulent use of media. Most previous watermarking schemes designed for diffusion models embed a secret key in the initial noise. The resulting pattern…

Computer Vision and Pattern Recognition · Computer Science 2025-04-30 Anubhav Jain , Yuya Kobayashi , Naoki Murata , Yuhta Takida , Takashi Shibuya , Yuki Mitsufuji , Niv Cohen , Nasir Memon , Julian Togelius

Backdoor-based watermarking schemes were proposed to protect the intellectual property of artificial intelligence models, especially deep neural networks, under the black-box setting. Compared with ordinary backdoors, backdoor-based…

Cryptography and Security · Computer Science 2022-08-31 Fangqi Li , Shilin Wang , Yun Zhu

Graph Neural Networks (GNNs) have achieved promising performance in various real-world applications. Building a powerful GNN model is not a trivial task, as it requires a large amount of training data, powerful computing resources, and…

Machine Learning · Computer Science 2022-11-15 Jing Xu , Stefanos Koffas , Oguzhan Ersoy , Stjepan Picek

Diffusion models have achieved remarkable progress in both image generation and editing. However, recent studies have revealed their vulnerability to backdoor attacks, in which specific patterns embedded in the input can manipulate the…

Computer Vision and Pattern Recognition · Computer Science 2025-06-06 Yu-Feng Chen , Tzuhsuan Huang , Pin-Yen Chiu , Jun-Cheng Chen

The rise of machine learning as a service and model sharing platforms has raised the need of traitor-tracing the models and proof of authorship. Watermarking technique is the main component of existing methods for protecting copyright of…

Cryptography and Security · Computer Science 2019-06-17 Ziqi Yang , Hung Dang , Ee-Chien Chang

With the increasing prevalence of Machine Learning as a Service (MLaaS) platforms, there is a growing focus on deep neural network (DNN) watermarking techniques. These methods are used to facilitate the verification of ownership for a…

Cryptography and Security · Computer Science 2024-07-19 Yuxuan Li , Sarthak Kumar Maharana , Yunhui Guo

Natural language generation (NLG) applications have gained great popularity due to the powerful deep learning techniques and large training corpus. The deployed NLG models may be stolen or used without authorization, while watermarking has…

Multimedia · Computer Science 2021-12-13 Tao Xiang , Chunlong Xie , Shangwei Guo , Jiwei Li , Tianwei Zhang

Machine learning models are being used in an increasing number of critical applications; thus, securing their integrity and ownership is critical. Recent studies observed that adversarial training and watermarking have a conflicting…

Machine Learning · Computer Science 2024-01-09 Janvi Thakkar , Giulio Zizzo , Sergio Maffeis