Embedding Watermarks into Deep Neural Networks
- 6 June 2017
- conference paper
- conference paper
- Published by Association for Computing Machinery (ACM)
- p. 269-277
- https://doi.org/10.1145/3078971.3078974
Abstract
Significant progress has been made with deep neural networks recently. Sharing trained models of deep neural networks has been a very important in the rapid progress of research and development of these systems. At the same time, it is necessary to protect the rights to shared trained models. To this end, we propose to use digital watermarking technology to protect intellectual property and detect intellectual property infringement in the use of trained models. First, we formulate a new problem: embedding watermarks into deep neural networks. Second, we propose a general framework for embedding a watermark in model parameters, using a parameter regularizer. Our approach does not impair the performance of networks into which a watermark is placed because the watermark is embedded while training the host network. Finally, we perform comprehensive experiments to reveal the potential of watermarking deep neural networks as the basis of this new research effort. We show that our framework can embed a watermark during the training of a deep neural network from scratch, and during fine-tuning and distilling, without impairing its performance. The embedded watermark does not disappear even after fine-tuning or parameter pruning; the watermark remains complete even after 65% of parameters are pruned.Keywords
Other Versions
This publication has 6 references indexed in Scilit:
- EIE: Efficient Inference Engine on Compressed Deep Neural NetworkPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2016
- CaffePublished by Association for Computing Machinery (ACM) ,2014
- MASK: Robust Local Features for Audio FingerprintingPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2012
- Ensemble Classifiers for Steganalysis of Digital MediaIEEE Transactions on Information Forensics and Security, 2011
- Accurate content-based video copy detection with efficient feature indexingPublished by Association for Computing Machinery (ACM) ,2011
- Long Short-Term MemoryNeural Computation, 1997