Deep Model Intellectual Property Protection With Compression-Resistant Model Watermarking.

Hewang Nie,Songfeng Lu,Junjun Wu,Jianxin Zhu
DOI: https://doi.org/10.1109/TAI.2024.3351116
2024-01-01
Abstract:Deep learning is considered a promising technology for empowering the Industrial Internet of Things (IIoT) with intelligence. However, the application of deep learning in the industrial IoT is accompanied by significant security challenges. Therefore, it has become crucial to investigate effective measures to provide secure deep learning services in IoT applications. In particular, the issue of intellectual property rights (IPR) protection is of great concern due to the illegal copying, redistribution, or misuse of deep neural network (DNN) models, which is one of the common ways that attackers target DNNs. However, existing defense mechanisms are easily detectable by attackers, rendering them ineffective. To address this issue, this paper presents a novel neural network model intellectual property protection scheme, called CRMW, which employs an image steganography algorithm and an image compression algorithm to generate a watermark dataset, which is subsequently embedded into the neural network model using feature consistency training. Compared with prior efforts, CRMW offers the advantage of being resistant to image compression and maintaining invisibility. The effectiveness of CRMW in providing secure deep learning services for IIoT has been validated through numerous experimental analyses.
What problem does this paper attempt to address?