Copyright protection for image classification models using pseudo-holographic watermarks
Yuliya Vybornova, Dmitry Ulyanov · 2023
With the growing number of solutions based on deep learning methods, there is a need to protect pretrained models against unauthorized distribution. For deep model watermarking, one of the most important criteria is to maintain the accuracy of predictions after embedding the protective information. In this paper, we propose a black-box watermarking method based on fine-tuning image classification models on a watermarking dataset, which is synthesized by superimposing pseudo-holograms on images of the original dataset. The proposed method allows to preserve the initial quality of classification, in addition, a series of experiments for five different models showed the invariance of the method to the architecture of a deep neural network. The conducted simulation of the most common attacks on watermarked models shows that adversarial attempts to completely remove the watermark are improbable without significant loss of model accuracy. Additionally, experimental results contain the selection of parameters, such as the number of triggers and original images in watermarking dataset, allowing to increase method efficiency.