Generation Management of White-Box DNN Model Watermarking
Ryu Furukawa, Shigeyuki Sakazawa · 2023
Techniques have been proposed to claim and protect copyrights by embedding watermarks on DNN (Deep Neural Network) models. However, there was insufficient verification of the generation management of watermarks, such as copyright indications for derived models. In this paper, we assume a white-box setting in which all parameters in the model are observable, verify the interference between watermarks when multiple watermarks are embedded, and propose an embedding method to reduce the interference. The experimental results confirm that watermarks can be embedded for two generations, Gen1 and Gen2. Furthermore, it was confirmed that the proposed method reduces the interference between watermarks. It was also found that embedding the watermark requires a number of parameters corresponding to the number of bits in the watermark. As a future issue, there was a difference in the magnitude of the embedding error of the watermark depending on the embedding layer.