English
Related papers

Related papers: Box-Free Model Watermarks Are Prone to Black-Box R…

200 papers

A significant number of machine learning models are vulnerable to model extraction attacks, which focus on stealing the models by using specially curated queries against the target model. This task is well accomplished by using part of the…

Cryptography and Security · Computer Science 2023-08-11 Harshit Shah , Aravindhan G , Pavan Kulkarni , Yuvaraj Govidarajulu , Manojkumar Parmar

Deep neural networks have had enormous impact on various domains of computer science, considerably outperforming previous state of the art machine learning techniques. To achieve this performance, neural networks need large quantities of…

Cryptography and Security · Computer Science 2018-09-05 Dorjan Hitaj , Luigi V. Mancini

Machine learning models constitute valuable intellectual property, yet remain vulnerable to model extraction attacks (MEA), where adversaries replicate their functionality through black-box queries. Model watermarking counters MEAs by…

Cryptography and Security · Computer Science 2025-11-18 Yaxin Xiao , Qingqing Ye , Zi Liang , Haoyang Li , RongHua Li , Huadi Zheng , Haibo Hu

Machine learning involves expensive data collection and training procedures. Model owners may be concerned that valuable intellectual property can be leaked if adversaries mount model extraction attacks. As it is difficult to defend against…

Cryptography and Security · Computer Science 2021-02-22 Hengrui Jia , Christopher A. Choquette-Choo , Varun Chandrasekaran , Nicolas Papernot

Deep Learning (DL) models have become crucial in digital transformation, thus raising concerns about their intellectual property rights. Different watermarking techniques have been developed to protect Deep Neural Networks (DNNs) from IP…

Cryptography and Security · Computer Science 2024-03-07 Alessandro Pegoraro , Carlotta Segna , Kavita Kumari , Ahmad-Reza Sadeghi

Watermark has been widely deployed by industry to detect AI-generated images. The robustness of such watermark-based detector against evasion attacks in the white-box and black-box settings is well understood in the literature. However, the…

Cryptography and Security · Computer Science 2025-02-20 Yuepeng Hu , Zhengyuan Jiang , Moyang Guo , Neil Zhenqiang Gong

Deep neural networks are valuable assets considering their commercial benefits and huge demands for costly annotation and computation resources. To protect the copyright of DNNs, backdoor-based ownership verification becomes popular…

Cryptography and Security · Computer Science 2023-09-12 Guanhao Gan , Yiming Li , Dongxian Wu , Shu-Tao Xia

Recent years have seen a surge in interest in digital content watermarking techniques, driven by the proliferation of generative models and increased legal pressure. With an ever-growing percentage of AI-generated content available online,…

Copyright protection for deep neural networks (DNNs) is an urgent need for AI corporations. To trace illegally distributed model copies, DNN watermarking is an emerging technique for embedding and verifying secret identity messages in the…

Cryptography and Security · Computer Science 2023-03-20 Yifan Yan , Xudong Pan , Mi Zhang , Min Yang

With the proliferation of AI agents in various domains, protecting the ownership of AI models has become crucial due to the significant investment in their development. Unauthorized use and illegal distribution of these models pose serious…

Computer Vision and Pattern Recognition · Computer Science 2025-01-14 Erjin Bao , Ching-Chun Chang , Hanrui Wang , Isao Echizen

The rapid proliferation of realistic deepfakes has raised urgent concerns over their misuse, motivating the use of defensive watermarks in synthetic images for reliable detection and provenance tracking. However, this defense paradigm…

Cryptography and Security · Computer Science 2026-01-26 Wei Song , Zhenchang Xing , Liming Zhu , Yulei Sui , Jingling Xue

With the rise of 3D Gaussian Splatting (3DGS), a variety of digital watermarking techniques, embedding either 1D bitstreams or 2D images, are used for copyright protection. However, the robustness of these watermarking techniques against…

Cryptography and Security · Computer Science 2025-08-12 Qingyuan Zeng , Shu Jiang , Jiajing Lin , Zhenzhong Wang , Kay Chen Tan , Min Jiang

Large language models (LLMs) demonstrate general intelligence across a variety of machine learning tasks, thereby enhancing the commercial value of their intellectual property (IP). To protect this IP, model owners typically allow user…

Cryptography and Security · Computer Science 2025-01-14 Kaiyi Pang , Tao Qi , Chuhan Wu , Minhao Bai , Minghu Jiang , Yongfeng Huang

Watermarking techniques are vital for protecting intellectual property and preventing fraudulent use of media. Most previous watermarking schemes designed for diffusion models embed a secret key in the initial noise. The resulting pattern…

Computer Vision and Pattern Recognition · Computer Science 2025-04-30 Anubhav Jain , Yuya Kobayashi , Naoki Murata , Yuhta Takida , Takashi Shibuya , Yuki Mitsufuji , Niv Cohen , Nasir Memon , Julian Togelius

We propose a novel multi-bit box-free watermarking method for the protection of Intellectual Property Rights (IPR) of GANs with improved robustness against white-box attacks like fine-tuning, pruning, quantization, and surrogate model…

Computer Vision and Pattern Recognition · Computer Science 2023-10-27 Jianwei Fei , Zhihua Xia , Benedetta Tondi , Mauro Barni

Creating a state-of-the-art deep-learning system requires vast amounts of data, expertise, and hardware, yet research into embedding copyright protection for neural networks has been limited. One of the main methods for achieving such…

Cryptography and Security · Computer Science 2020-04-27 William Aiken , Hyoungshick Kim , Simon Woo

Watermarking generative models consists of planting a statistical signal (watermark) in a model's output so that it can be later verified that the output was generated by the given model. A strong watermarking scheme satisfies the property…

Machine Learning · Computer Science 2025-05-29 Hanlin Zhang , Benjamin L. Edelman , Danilo Francati , Daniele Venturi , Giuseppe Ateniese , Boaz Barak

Watermarking enables GenAI providers to verify whether content was generated by their models. A watermark is a hidden signal in the content, whose presence can be detected using a secret watermark key. A core security threat are forgery…

Cryptography and Security · Computer Science 2026-05-12 Toluwani Aremu , Noor Hussein , Munachiso Nwadike , Samuele Poppi , Jie Zhang , Karthik Nandakumar , Neil Gong , Nils Lukas

To protect the intellectual property of well-trained deep neural networks (DNNs), black-box watermarks, which are embedded into the prediction behavior of DNN models on a set of specially-crafted samples and extracted from suspect models…

Cryptography and Security · Computer Science 2024-09-04 Yifan Lu , Wenxuan Li , Mi Zhang , Xudong Pan , Min Yang

A watermarking algorithm is proposed in this paper to address the copyright protection issue of implicit 3D models. The algorithm involves embedding watermarks into the images in the training set through an embedding network, and…

Cryptography and Security · Computer Science 2023-09-22 Lifeng Chen , Jia Liu , Yan Ke , Wenquan Sun , Weina Dong , Xiaozhong Pan