An Improved Backdoor Watermark Embedding Method Based on UNet

Yinghua Huang, Zhibo Du, Shichun Chen · 2025

Producing datasets is usually time-consuming and labor-intensive, and how to protect their copyrights is of great significance. U-shaped Network has been widely used in neural network models in recent years, and when it comes to the specific application in digital watermarking, practical problems such as the complexity of watermarked images and the loss of detailed features will affect the classification accuracy of the model. To address the above problems, this paper proposes an improved backdoor watermark embedding method based on UNet. First, in the process of embedding the watermark, the UNet downsampling module is improved and channel attention is introduced, which enables the model to understand the image better and provides a more targeted feature representation for the subsequent watermark verification; in addition, while applying the traditional convolution, dilated convolution is introduced, which both expands the sensory field and preserves the spatial features such as position. Finally, a black-box verification algorithm with a backdoor attack mechanism is used to verify whether a suspicious model uses a watermarked dataset based on this special mapping relationship. Experimental results show that the model in this paper works better than the original UNet model and is more usable and effective.

Read the paper · More papers on PaperTik