Watermark Removal Scheme Based on Neural Network Model Pruning

被引:1
|
作者
Gu, Wenwen [1 ]
Qian, Haifeng [1 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
来源
2022 5TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND NATURAL LANGUAGE PROCESSING, MLNLP 2022 | 2022年
关键词
Deep neural network; Digital watermarking; Model pruning; Watermark removal;
D O I
10.1145/3578741.3578832
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, due to the rapid development of information technology, machine learning is widely used in various fields. Training deep neural network models is a very expensive process, which requires a lot of training data and hardware resources. Therefore, DNN models can be considered the intellectual property rights of model owners and need to be protected. More and more watermarking algorithms have been studied to embed into neural network models to protect the ownership of the models. At the same time, to test the robustness of the watermark, watermarking attack algorithms have emerged. In this paper, we firstly find the unexpected sensitivity of watermarked models, that is, they are more susceptible to adversarial disturbances than unwatermarked models, and then propose a model repair method based on neural network model pruning. By pruning some sensitive neurons to remove the watermark, the success rate of the watermark can be reduced to a certain extent, and on this basis, it verifies that it can effectively avoid model ownership detection.
引用
收藏
页码:377 / 382
页数:6
相关论文
共 50 条
  • [21] A Pruning Neural Network Model in Credit Classification Analysis
    Tang, Yajiao
    Ji, Junkai
    Gao, Shangce
    Dai, Hongwei
    Yu, Yang
    Todo, Yuki
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2018, 2018 : 9390410
  • [22] A model reference adaptive control scheme based on neural network
    Hongjie, Hu
    Yuqiao, Miao
    SYSTEMS MODELING AND SIMULATION: THEORY AND APPLICATIONS, ASIA SIMULATION CONFERENCE 2006, 2007, : 73 - +
  • [23] A robust digital watermark extracting method based on neural network
    Guo, LH
    Yang, ST
    Li, JH
    CHINESE JOURNAL OF ELECTRONICS, 2003, 12 (04): : 652 - 655
  • [24] Adaptive watermark scheme with RBF neural networks
    Zhang, ZM
    Li, RY
    Wang, L
    PROCEEDINGS OF 2003 INTERNATIONAL CONFERENCE ON NEURAL NETWORKS & SIGNAL PROCESSING, PROCEEDINGS, VOLS 1 AND 2, 2003, : 1517 - 1520
  • [25] Nonlinear systems modelling based on self-organizing fuzzy neural network with hierarchical pruning scheme
    Zhou, Hongbiao
    Zhang, Yu
    Duan, Weiping
    Zhao, Huanyu
    APPLIED SOFT COMPUTING, 2020, 95
  • [26] Visible watermark removal scheme based on reversible data hiding and image inpainting
    Qin, Chuan
    He, Zhihong
    Yao, Heng
    Cao, Fang
    Gao, Liping
    SIGNAL PROCESSING-IMAGE COMMUNICATION, 2018, 60 : 160 - 172
  • [27] A Neural Network Pruning Approach based on Compressive Sampling
    Yang, Jie
    Bouzerdoum, Abdesselam
    Phung, Son Lam
    IJCNN: 2009 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, VOLS 1- 6, 2009, : 3213 - 3220
  • [28] Pruning method for a cluster-based neural network
    Ranney, K
    Khatri, H
    Nguyen, L
    Sichina, J
    ALGORITHMS FOR SYNTHETIC APERTURE RADAR IMAGERY VII, 2000, 4053 : 274 - 279
  • [29] Channel pruning based on convolutional neural network sensitivity
    Yang, Chenbin
    Liu, Huiyi
    NEUROCOMPUTING, 2022, 507 : 97 - 106
  • [30] Neural network pruning based on channel attention mechanism
    Hu, Jianqiang
    Liu, Yang
    Wu, Keshou
    CONNECTION SCIENCE, 2022, 34 (01) : 2201 - 2218