Watermark Removal Scheme Based on Neural Network Model Pruning

被引:1
|
作者
Gu, Wenwen [1 ]
Qian, Haifeng [1 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
关键词
Deep neural network; Digital watermarking; Model pruning; Watermark removal;
D O I
10.1145/3578741.3578832
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, due to the rapid development of information technology, machine learning is widely used in various fields. Training deep neural network models is a very expensive process, which requires a lot of training data and hardware resources. Therefore, DNN models can be considered the intellectual property rights of model owners and need to be protected. More and more watermarking algorithms have been studied to embed into neural network models to protect the ownership of the models. At the same time, to test the robustness of the watermark, watermarking attack algorithms have emerged. In this paper, we firstly find the unexpected sensitivity of watermarked models, that is, they are more susceptible to adversarial disturbances than unwatermarked models, and then propose a model repair method based on neural network model pruning. By pruning some sensitive neurons to remove the watermark, the success rate of the watermark can be reduced to a certain extent, and on this basis, it verifies that it can effectively avoid model ownership detection.
引用
收藏
页码:377 / 382
页数:6
相关论文
共 50 条
  • [1] Fused Pruning based Robust Deep Neural Network Watermark Embedding
    Li, Tengfei
    Wang, Shuo
    Jing, Huiyun
    Lian, Zhichao
    Meng, Shunmei
    Li, Qianmu
    2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 2475 - 2481
  • [2] Adaptive model and neural network based watermark identification
    McLauchlan, Lifford
    Mehruebeoglu, Mehruebe
    MATHEMATICS OF DATA/IMAGE PATTERN RECOGNITION, COMPRESSION, CODING, AND ENCRYPTION X, WITH APPLICATIONS, 2007, 6700
  • [3] Neural-network-based zero-watermark scheme for digital images
    Sang, J.
    Liao, Xiaofeng
    Alam, M. S.
    OPTICAL ENGINEERING, 2006, 45 (09)
  • [4] A robust copyright_protection (Digital watermark) scheme based on neural network
    Chen, GH
    Horng, GB
    Chen, TH
    7TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL XV, PROCEEDINGS: COMMUNICATION, CONTROL, SIGNAL AND OPTICS, TECHNOLOGIES AND APPLICATIONS, 2003, : 345 - 349
  • [5] A Neural Network Based Outlier Identification and Removal Scheme
    Ferdowsi, H.
    Jagannathan, S.
    Zawodniok, M.
    2013 IEEE INTERNATIONAL CONFERENCE ON PROGNOSTICS AND HEALTH MANAGEMENT, 2013,
  • [6] GLCM and neural network based watermark identification
    McLauchlan, Lifford
    Mehrubeoglu, Mehrube
    MATHEMATICS OF DATA/IMAGE PATTERN RECOGNITION, COMPRESSION, AND ENCRYPTION WITH APPLICATIONS XI, 2008, 7075
  • [7] Neural network based watermark embedding and identification
    McLauchlan, Lifford
    Mehrubeoglu, Mehrube
    MATHEMATICS OF DATA/IMAGE PATTERN RECOGNITION, COMPRESSION, AND ENCRYPTION WITH APPLICATIONS XI, 2008, 7075
  • [8] ScoringNet: A Neural Network Based Pruning Criteria for Structured Pruning
    Wang S.
    Zhang Z.
    Scientific Programming, 2023, 2023
  • [9] An Incremental Scheme with Weight Pruning to Train Deep Neural Network
    Guo, Haonan
    Yan, Zhicong
    Yang, Jichao
    Li, Shenghong
    COMMUNICATIONS, SIGNAL PROCESSING, AND SYSTEMS, CSPS 2018, VOL III: SYSTEMS, 2020, 517 : 295 - 302
  • [10] Dynamic digital watermark technique based on neural network
    Gu Tao
    Li Xu
    INDEPENDENT COMPONENT ANALYSES, WAVELETS, UNSUPERVISED NANO-BIOMIMETIC SENSORS, AND NEURAL NETWORKS VI, 2008, 6979