arXiv:2502.05931cs.LGcs.AI2025-02

用密码学水印保护脑电神经网络,防抄袭且不影响诊断精度。

Protecting Intellectual Property of EEG-based Neural Networks with Watermarking

  • 基于抗碰撞哈希与公钥加密,在训练时嵌入水印。
  • 水印保留率超90%,误删水印导致精度损失超10%。
  • 适合医疗与脑机接口领域模型版权保护。

基于脑电的神经网络在医疗诊断和脑机接口中至关重要,但其依赖敏感神经生理数据且开发成本高,面临严重知识产权风险。现有水印方法(尤其使用抽象触发集)缺乏可靠认证,难以应对脑电模型的独特挑战。本文提出一种基于密码学奇异滤波器的水印框架,结合抗碰撞哈希与公钥加密,在训练阶段嵌入水印,实现≤5%的性能下降(任务准确率),并保证100%水印检测率。该框架在微调、迁移学习和神经元剪枝等对抗攻击下仍保持稳定,水印状态分类准确率高于90%,而主任务性能下降更快,有效遏制移除行为。在无原始密钥情况下无法嵌入二次水印,否则导致>10%精度损失(在EEGNet和CCNN模型中)。基于密码学哈希的认证机制显著降低暴力破解成功率。在DEAP数据集上对CCNN、EEGNet、TSception等模型测试,空嵌入准确率>99.4%,几乎消除误报。通过融合奇异滤波器与脑电适配,本工作填补了神经生理模型知识产权保护的关键空白,为医疗与生物识别应用提供安全、防篡改的解决方案。

原文摘要 · Abstract (English)

EEG-based neural networks, pivotal in medical diagnosis and brain-computer interfaces, face significant intellectual property (IP) risks due to their reliance on sensitive neurophysiological data and resource-intensive development. Current watermarking methods, particularly those using abstract trigger sets, lack robust authentication and fail to address the unique challenges of EEG models. This paper introduces a cryptographic wonder filter-based watermarking framework tailored for EEG-based neural networks. Leveraging collision-resistant hashing and public-key encryption, the wonder filter embeds the watermark during training, ensuring minimal distortion ($\leq 5\%$ drop in EEG task accuracy) and high reliability (100\% watermark detection). The framework is rigorously evaluated against adversarial attacks, including fine-tuning, transfer learning, and neuron pruning. Results demonstrate persistent watermark retention, with classification accuracy for watermarked states remaining above 90\% even after aggressive pruning, while primary task performance degrades faster, deterring removal attempts. Piracy resistance is validated by the inability to embed secondary watermarks without severe accuracy loss ( $>10\%$ in EEGNet and CCNN models). Cryptographic hashing ensures authentication, reducing brute-force attack success probabilities. Evaluated on the DEAP dataset across models (CCNN, EEGNet, TSception), the method achieves $>99.4\%$ null-embedding accuracy, effectively eliminating false positives. By integrating wonder filters with EEG-specific adaptations, this work bridges a critical gap in IP protection for neurophysiological models, offering a secure, tamper-proof solution for healthcare and biometric applications. The framework's robustness against adversarial modifications underscores its potential to safeguard sensitive EEG models while maintaining diagnostic utility.

脑电模型水印技术知识产权

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。