Watermark Removal Scheme Based on Neural Network Model Pruning

被引:1
|
作者
Gu, Wenwen [1 ]
Qian, Haifeng [1 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
来源
2022 5TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND NATURAL LANGUAGE PROCESSING, MLNLP 2022 | 2022年
关键词
Deep neural network; Digital watermarking; Model pruning; Watermark removal;
D O I
10.1145/3578741.3578832
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, due to the rapid development of information technology, machine learning is widely used in various fields. Training deep neural network models is a very expensive process, which requires a lot of training data and hardware resources. Therefore, DNN models can be considered the intellectual property rights of model owners and need to be protected. More and more watermarking algorithms have been studied to embed into neural network models to protect the ownership of the models. At the same time, to test the robustness of the watermark, watermarking attack algorithms have emerged. In this paper, we firstly find the unexpected sensitivity of watermarked models, that is, they are more susceptible to adversarial disturbances than unwatermarked models, and then propose a model repair method based on neural network model pruning. By pruning some sensitive neurons to remove the watermark, the success rate of the watermark can be reduced to a certain extent, and on this basis, it verifies that it can effectively avoid model ownership detection.
引用
收藏
页码:377 / 382
页数:6
相关论文
共 50 条
  • [31] Convolutional neural network pruning based on misclassification cost
    Ahmadluei, Saeed
    Faez, Karim
    Masoumi, Behrooz
    JOURNAL OF SUPERCOMPUTING, 2023, 79 (18): : 21185 - 21234
  • [32] Convolutional neural network pruning based on misclassification cost
    Saeed Ahmadluei
    Karim Faez
    Behrooz Masoumi
    The Journal of Supercomputing, 2023, 79 : 21185 - 21234
  • [33] FVW: Finding ValuableWeight on Deep Neural Network for Model Pruning
    Zhu, Zhiyu
    Chen, Huaming
    Jin, Zhibo
    Wang, Xinyi
    Zhang, Jiayu
    Xue, Minhui
    Lu, Qinghua
    Shen, Jun
    Choo, Kim-Kwang Raymond
    PROCEEDINGS OF THE 32ND ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2023, 2023, : 3657 - 3666
  • [34] A novel wavelet watermark algorithm based on neural network image scramble
    Zhao, J
    Zhao, Q
    Zhou, MQ
    Pan, JS
    ADVANCES IN NATURAL COMPUTATION, PT 2, PROCEEDINGS, 2005, 3611 : 346 - 351
  • [35] A blind algorithm of digital watermark in wavelet domain based on neural network
    Hou, Xiang-Yong
    WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING, VOL 1 AND 2, 2006, : 565 - 570
  • [36] A Chinese word segmentation scheme based on a deep neural network model
    Xu F.
    Zhang X.
    Xin Z.
    Harbin Gongcheng Daxue Xuebao/Journal of Harbin Engineering University, 2019, 40 (09): : 1662 - 1666
  • [37] A crack identification scheme based on neural network surrogate model and XFEM
    Zhong, Yudong
    Zeng, Xue
    Hou, Junjian
    Wang, Ruolan
    Wang, Liangwen
    Zhao, Dengfeng
    He, Wenbin
    Zheng, Yinan
    PHYSICA SCRIPTA, 2024, 99 (10)
  • [38] Neural network based system for optimal watermark embodiment in audio signals
    Milosavljevic, MM
    Uzunovic, P
    NEUREL 2004: SEVENTH SEMINAR ON NEURAL NETWORK APPLICATIONS IN ELECTRICAL ENGINEERING, PROCEEDINGS, 2004, : 61 - 61
  • [39] ROBUST BLIND WATERMARK ALGORITHM OF COLOR IMAGE BASED ON NEURAL NETWORK
    Hu, Xuelong
    Lian, Xu
    Chen, Lin
    Zheng, Yongai
    2008 INTERNATIONAL CONFERENCE ON NEURAL NETWORKS AND SIGNAL PROCESSING, VOLS 1 AND 2, 2007, : 430 - +
  • [40] Exploiting the Relationship between Pruning Ratio and Compression Effect for Neural Network Model Based on TensorFlow
    Liu, Bo
    Wu, Qilin
    Zhang, Yiwen
    Cao, Qian
    SECURITY AND COMMUNICATION NETWORKS, 2020, 2020