Watermarking Neural Network with Compensation Mechanism

Le Feng,Xinpeng Zhang
DOI: https://doi.org/10.1007/978-3-030-55393-7_33
2020-01-01
Abstract:In recent years, the rapid development of neural networks has also brought his intellectual property (IP) protection. Embedding a watermark in a neural network is an effective scheme to protect its IP. In this paper, we propose a new watermark embedding scheme with compensation mechanism that is different from the previous regularization embedding. First, we select the weights of the watermark to be embedded pseudo-randomly. Then, we perform an orthogonal transformation on the selected weights, and embed the watermark by the binarization method in the obtained coefficients, and use the inverse orthogonal transformation on the watermarked coefficients to obtain the watermarked weights. Finally, we propose a model fine-tuning scheme with compensation mechanism, which can eliminate the slight accuracy degradation caused by binarization without destroying the watermark in the model. In our scheme, due to the concealment of watermark embedding location, it can overcome the defects of previous schemes which cannot resist watermark overwriting attack. Moreover, compared with the regularization embedding method, our scheme uses the fine-tuning with compensation mechanism, which requires less embedding cost and is more stable. In addition, it has achieved favorable performance in resisting weight pruning attack, weight fine-tuning and fidelity evaluation.
What problem does this paper attempt to address?