Method for Protection of Deep Learning Models using Digital Watermarking
Yuliya Vybornova, Dmitry Ulyanov · 2022 VIII International Conference on Information Technology and Nanotechnology (ITNT) · 2022
In this paper, a new method for protection of copyright on pretrained deep neural networks is proposed. The main idea is to embed a digital watermark into a pretrained model by fine-tuning it on a unique trigger set formed by synthesizing pseudo-holographic images (pseudo-holograms) and embedding them into raster images of the original dataset. A pseudo-hologram is a special type of a two-dimensional signal, which encodes a binary sequence. On the example of binary classification, we propose to produce various pseudo-holograms based on the same sequence for one class and on another sequence for the second class. Schemes for preparing the trigger set, model watermarking, and the further copyright verification are proposed. The experimental study is aimed at comparing various embedding strategies in the task of trigger set construction. Experiments were also performed for various model architectures to demonstrate high method efficiency.