Watermarks for Generative Adversarial Network Based on Steganographic Invisible Backdoor

Yuwei Zeng, Jingxuan Tan, Zhengxin You, Zhenxing Qian, Xinpeng Zhang · 2023

Model watermarking has become an important solution to protect the intellectual property right (IPR) of deep neural networks (DNN) models. However, there are few researches on the IPR protection of generative adversarial networks (GAN), which are widely used to generate photorealistic images. In the current backdoor-based watermarking method for GAN models, the trigger pattern of the watermark is easy to be detected and invalidated by the adversary, which may fail to achieve IPR protection. To address this drawback, we propose a new GAN model watermarking method, where an invisible backdoor based on steganography is injected into the target GAN model as a watermark. Experimentally, the proposed method effectively trades off the performance of GAN on original task and the robustness of watermarking for removal attacks. Moreover, the generated triggers can effectively resist being detected by attackers.

Read the paper · More papers on PaperTik