Anti-pruning multi-watermarking for ownership proof of steganographic autoencoders.

Journal of Information Security and Applications(2023)

引用 0|浏览1
暂无评分
摘要
Model watermarking Model watermarking is a method for embedding watermark information into a neural network model. It proves the ownership of the model without affecting its performance. Since there are plenty of attacks against model pruning, it becomes more significant to design anti-pruning model watermarking algo-rithms. In this paper, multiple watermark embedding is performed to protect the model copyright for the image steganography auto-encoder model "Hiding Data with Deep Networks" (HiDDeN). Firstly, the appropriate model weights are selected by employing three classical model pruning algorithms of model weights. Secondly, the model watermark is spread by using Discrete Cosine Transform (DCT)-based image watermarking algorithm, which improves the noise and pruning resistance of the model watermark. Finally, the model watermark is embedded to the 4th and 5th decimal places of the selected model weights. The experimental results demonstrate that the proposed algorithm has a good robustness against model pruning without affecting the watermark extraction performance of the auto-encoder network model. Even with the embedded model watermark, the decoder's watermark extraction accuracy is still higher than 0.9993. and the autoencoder is still valuable when the model weights are pruned by 40%. Furthermore, the proposed algorithm has a certain degree of improve-ments in watermarking capacity.
更多
查看译文
关键词
Anti-pruning, Auto-encoder, Multiple watermarking, HiDDeN model, DCT
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要