Watermarks for Generative Adversarial Network Based on Steganographic Invisible Backdoor.

Yuwei Zeng,Jingxuan Tan,Zhengxin You,Zhenxing Qian,Xinpeng Zhang
DOI: https://doi.org/10.1109/icme55011.2023.00211
2023-01-01
Abstract:Model watermarking has become an important solution to protect the intellectual property right (IPR) of deep neural networks (DNN) models. However, there are few researches on the IPR protection of generative adversarial networks (GAN), which are widely used to generate photorealistic images. In the current backdoor-based watermarking method for GAN models, the trigger pattern of the watermark is easy to be detected and invalidated by the adversary, which may fail to achieve IPR protection. To address this drawback, we propose a new GAN model watermarking method, where an invisible backdoor based on steganography is injected into the target GAN model as a watermark. Experimentally, the proposed method effectively trades off the performance of GAN on original task and the robustness of watermarking for removal attacks. Moreover, the generated triggers can effectively resist being detected by attackers.
What problem does this paper attempt to address?