A Novel Watermarking Mechanism for Deep Learning Models Based on Chaotic Boundaries

Zi-Jie Huang,Ying-Qian Zhang,Yi-Ran Jia
DOI: https://doi.org/10.1109/ismict51748.2021.9434906
2021-01-01
Abstract:With the development of deep learning models, how to protect model owners intellectual property rights has become a realistic problem. Black-box watermarking technology provides an idea which allows model owners to validate a suspect model through trigger sets. Usually, the trigger set is formed by adding Gaussian noise to the data set or manually marking the data set. In this paper, we propose a novel watermarking mechanism for deep learning models. Firstly, CGAN is used to generate the data at classification boundaries. Secondly, Chaos automatic annotation generates chaotic values through iterations is used to label these extra data in boundaries, so as to distinguish the watermarked model and non-watermarked model. Compared with former trigger sets, the labeling of our trigger set is automatic, and due to the excellent characteristics of chaos, the chaotic value of the trigger set is difficult to predict in a long term. The chaotic sequence is sensitive to the initial value. Therefore, the initial value and the rule for selecting the chaotic value form our key space. Even if the trigger set is leaked, as long as the key is not leaked, the attacker cannot get our chaotic value. In addition, experiments and simulations show that the mechanism is effective, secure and robust. It can resist fine-tuning attacks, compression attacks, fraudulent ownership claim attacks and overwriting attacks.
What problem does this paper attempt to address?