WatCOM: Unconscious Watermarking for Semantic Communication Intellectual Property Protection
Xiao Kang Yang, Yuanhang He, Gaolei Li, Jianhua Li · 2025
Semantic Communication (SC) enhances communication efficacy by abstracting and decoding semantic information via shared knowledge instead of bitstream, while considerably reducing redundancy and reinforcing efficiency in downstream tasks including image recognition, language processing, internet of things, etc. Due to the extensive data collection, processing, and training, the SC shared knowledge is invaluable Intellectual Property (IP), and despite the owners' desire to prevent misuse, the knowledge still remains vulnerable to theft while related IP protection has yet to be explored. To bridge this gap, we propose WatCom, the first SC IP protection methodology via watermarking. Specifically, we implant a stealthy backdoor into the semantic shared knowledge to verify model ownership, which can solely be activated by the owner-exclusive implicit trigger to validate ownership. The backdoor is implanted by poisoning-training strategy, facilitating SC system to respond normally to regular inputs while producing verification outputs (i.e., backdoor activation) for trigger-infected samples. To ensure imperceptibility, we leverage one generator to synthesize infected data that is nearly indistinguishable from regular data, which thereby obfuscates the verification information presence and enhances security against adversarial detection. Experiments based on multiple datasets and systems demonstrate WatCom can effectively verify system ownership (IP Verification Rate$\sim 100 \%$) while maintaining transmission efficacy (Peak Signal-to-Noise Ratio drop$< 2 ~\text{dB}$).