Structural Watermarking to Deep Neural Networks via Network Channel Pruning

被引:5
|
作者
Zhao, Xiangyu [1 ]
Yao, Yinzhe [1 ]
Wu, Hanzhou [1 ]
Zhang, Xinpeng [1 ]
机构
[1] Shanghai Univ, Shanghai 200444, Peoples R China
基金
中国国家自然科学基金;
关键词
Watermarking; deep neural networks; ownership protection; deep learning; security;
D O I
10.1109/WIFS53200.2021.9648376
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In order to protect the intellectual property (IP) of deep neural networks (DNNs), many existing DNN watermarking techniques either embed watermarks directly into the DNN parameters or insert backdoor watermarks by fine-tuning the DNN parameters, which, however, cannot resist against various attack methods that remove watermarks by altering DNN parameters. In this paper, we bypass such attacks by introducing a structural watermarking scheme that utilizes channel pruning to embed the watermark into the host DNN architecture instead of crafting the DNN parameters. To be specific, during watermark embedding, we prune the internal channels of the host DNN with the channel pruning rates controlled by the watermark. During watermark extraction, the watermark is retrieved by identifying the channel pruning rates from the architecture of the target DNN model. Due to the superiority of pruning mechanism, the performance of the DNN model on its original task is reserved during watermark embedding. Experimental results have shown that, the proposed work enables the embedded watermark to be reliably recovered and provides a sufficient payload, without sacrificing the usability of the DNN model. It is also demonstrated that the proposed work is robust against common transforms and attacks designed for conventional watermarking approaches.
引用
收藏
页码:14 / 19
页数:6
相关论文
共 50 条
  • [41] Automatic Pruning Rate Derivation for Structured Pruning of Deep Neural Networks
    Sakai, Yasufumi
    Iwakawa, Akinori
    Tabaru, Tsuguchika
    Inoue, Atsuki
    Kawaguchi, Hiroshi
    2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 2561 - 2567
  • [42] Watermarking Deep Neural Networks for Embedded Systems
    Guo, Jia
    Potkonjak, Miodrag
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD) DIGEST OF TECHNICAL PAPERS, 2018,
  • [43] Watermarking Deep Neural Networks with Greedy Residuals
    Liu, Hanwen
    Weng, Zhenyu
    Zhu, Yuesheng
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139
  • [44] Watermarking Deep Neural Networks in Image Processing
    Quan, Yuhui
    Teng, Huan
    Chen, Yixin
    Ji, Hui
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2021, 32 (05) : 1852 - 1865
  • [45] Speech watermarking using Deep Neural Networks
    Pavlovic, Kosta
    Kovacevic, Slavko
    Durovic, Igor
    2020 28TH TELECOMMUNICATIONS FORUM (TELFOR), 2020, : 292 - 295
  • [46] ADVERSARIAL WATERMARKING TO ATTACK DEEP NEURAL NETWORKS
    Wang, Gengxing
    Chen, Xinyuan
    Xu, Chang
    2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 1962 - 1966
  • [47] Towards performance-maximizing neural network pruning via global channel attention
    Wang, Yingchun
    Guo, Song
    Guo, Jingcai
    Zhang, Jie
    Zhang, Weizhan
    Yan, Caixia
    Zhang, Yuanhong
    NEURAL NETWORKS, 2024, 171 : 104 - 113
  • [48] DEEP LEARNING BASED METHOD FOR PRUNING DEEP NEURAL NETWORKS
    Li, Lianqiang
    Zhu, Jie
    Sun, Ming-Ting
    2019 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA & EXPO WORKSHOPS (ICMEW), 2019, : 312 - 317
  • [49] A survey of Deep Neural Network watermarking techniques
    Li, Yue
    Wang, Hongxia
    Barni, Mauro
    NEUROCOMPUTING, 2021, 461 : 171 - 193
  • [50] Customized and Robust Deep Neural Network Watermarking
    Chien, Tzu-Yun
    Shen, Chih-Ya
    PROCEEDINGS OF THE 17TH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, WSDM 2024, 2024, : 134 - 142