A Robust Watermarking Method For Image Processing Models

Minghua Hou,Linlin Tang,Shuhan Qi,Yang Liu
DOI: https://doi.org/10.1109/ICDIS55630.2022.00019
2022-01-01
Abstract:Sharing neural network models in some platforms and communities has become a popular trend, but they will inevitably suffer from malicious theft of models, If the attacker knows the structure and weights of the model, the model can be easily modified, how to protect the intellectual property rights of the deep models has become a serious problem. The appearance of model watermarking provides a technical possibility for the intellectual property protection of neural network models, and it provides us a reliable method of verifying model ownership when the model's intellectual property rights are infringed. Based on previous work, this paper proposes a new watermarking method for image processing models, which embeds the watermark information into the two chroma channels of the YCbCr color space of image processing model's output images. The proposed method can verify the model ownership in black-box case, which has strong robustness and resistance to common model compression and model fine-tuning attacks.
What problem does this paper attempt to address?