DeepVerifier: Robust Watermarking of Deep Neural Networks Based on Black-Box and White-Box Reasoning

Twinkle Tyagi, Kedar Nath Singh, Amit Kumar Singh, Brij Bhooshan Gupta · IEEE Transactions on Computational Social Systems · 2025

Recently, deep learning models have become the backbone of critical applications, serving as a key asset across various domains such as social media, healthcare, finance, and retail. Consequently, the market for these models has expanded exponentially, with platforms emerging to facilitate secure transactions and collaborations between model developers and end users. However, this convenience has also given rise to significant challenges, particularly copyright infringement and ownership conflicts. To address these issues, we propose a unified framework,DeepVerifier, which integrates black-box and white-box watermarking. Cryptographic hash functions (SHA) and chaotic maps are utilized to generate a unique secret message. This message, called the watermark, is then divided into$k$blocks. We determine the optimal embedding locations as the model parameters with the lowest gradient weights, after which the blocks are imperceptibly concealed within selected weights. To evaluate the effectiveness ofDeepVerifier, we assess the watermarked model in both black-box and white-box scenarios on the receiver’s end. Experimental results demonstrate thatDeepVerifierenables two-stage ownership verification of notable models against various attacks while deteriorating the original task accuracy by less than 0.5% on average. To the best of our knowledge, this is the first attempt to develop a method for the copyright protection of deep neural network (DNN) models using the lowest-gradient-based embedding of a generated fused watermark and two-stage ownership verification via watermarking.

Read the paper · More papers on PaperTik