We propose a white-box, multi-bit watermarking method that can achieve large payload and improved robustness with respect to existing algorithms. The design of an effective multi-bit watermarking algorithm hinges upon finding a good trade-off between the three fundamental requirements forming the watermarking trade-off triangle, namely, robustness against network modifications, payload, and unobtrusiveness, ensuring minimal impact on the performance of the watermarked network. In this paper, we first revisit the nature of the watermarking trade-off triangle for the DNN case, then we exploit our findings to propose a white-box, multi-bit watermarking method achieving very large payload and strong robustness against network modification. In the proposed system, the weights hosting the watermark are set prior to training, making sure that their amplitude is large enough to bear the target payload and survive network modifications, notably retraining, and are left unchanged throughout the training process. The distribution of the weights carrying the watermark is theoretically optimised to ensure the secrecy of the watermark and make sure that the watermarked weights are indistinguishable from the non-watermarked ones. The proposed method can achieve outstanding performance, with no significant impact on network accuracy, including robustness against network modifications, retraining and transfer learning, while ensuring a payload which is out of reach of state of the art methods achieving a lower - or at most comparable - robustness.

Tondi, B., Costanzo, A., Barni, M. (2024). Robust and Large-Payload DNN Watermarking via Fixed, Distribution-Optimized, Weights. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 1-17 [10.1109/TDSC.2024.3426957].

Robust and Large-Payload DNN Watermarking via Fixed, Distribution-Optimized, Weights

Tondi B.;Costanzo A.;Barni M.
2024-01-01

Abstract

We propose a white-box, multi-bit watermarking method that can achieve large payload and improved robustness with respect to existing algorithms. The design of an effective multi-bit watermarking algorithm hinges upon finding a good trade-off between the three fundamental requirements forming the watermarking trade-off triangle, namely, robustness against network modifications, payload, and unobtrusiveness, ensuring minimal impact on the performance of the watermarked network. In this paper, we first revisit the nature of the watermarking trade-off triangle for the DNN case, then we exploit our findings to propose a white-box, multi-bit watermarking method achieving very large payload and strong robustness against network modification. In the proposed system, the weights hosting the watermark are set prior to training, making sure that their amplitude is large enough to bear the target payload and survive network modifications, notably retraining, and are left unchanged throughout the training process. The distribution of the weights carrying the watermark is theoretically optimised to ensure the secrecy of the watermark and make sure that the watermarked weights are indistinguishable from the non-watermarked ones. The proposed method can achieve outstanding performance, with no significant impact on network accuracy, including robustness against network modifications, retraining and transfer learning, while ensuring a payload which is out of reach of state of the art methods achieving a lower - or at most comparable - robustness.
2024
Tondi, B., Costanzo, A., Barni, M. (2024). Robust and Large-Payload DNN Watermarking via Fixed, Distribution-Optimized, Weights. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 1-17 [10.1109/TDSC.2024.3426957].
File in questo prodotto:
File Dimensione Formato  
Robust_and_Large-Payload_DNN_Watermarking_via_Fixed_Distribution-Optimized_Weights.pdf

non disponibili

Tipologia: Pre-print
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 3.19 MB
Formato Adobe PDF
3.19 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11365/1267394