arXiv:2505.04977cs.CRcs.AI2025-05中稿 · ACM ASIA Conferenc…被引 5

用密码链生成抗攻击的深度模型水印,提升版权保护可靠性。

ChainMarks: Securing DNN Watermark with Cryptographic Chain

  • 通过密钥迭代哈希生成带数字签名的触发样本作为水印数据集。
  • 在相同水印准确率下,水印存在概率更高,且对移除攻击更鲁棒。
  • 采用两阶段蒙特卡洛方法确定水印存在性,决策更精准适合版权验证。

随着深度神经网络(DNN)模型广泛应用,动态水印技术被用于保护模型知识产权。然而,现有水印方案易受水印移除和模糊性攻击,且缺乏明确的水印存在判断标准。本文提出安全的DNN水印方案ChainMarks,通过在触发输入中引入密码链生成鲁棒水印,并采用两阶段蒙特卡洛方法判定水印存在性。首先,使用秘密密钥反复应用哈希函数生成触发输入,其目标标签由模型所有者数字签名生成;然后,将原始数据与水印数据集联合训练得到水印模型。验证时,比较触发输入的预测标签与目标标签,并基于特定模型的分类置信度设定更精确的决策阈值。实验表明,ChainMarks在鲁棒性与安全性上优于现有先进水印方案,在相同水印准确率下提供更高的水印存在概率保证。

原文摘要 · Abstract (English)

With the widespread deployment of deep neural network (DNN) models, dynamic watermarking techniques are being used to protect the intellectual property of model owners. However, recent studies have shown that existing watermarking schemes are vulnerable to watermark removal and ambiguity attacks. Besides, the vague criteria for determining watermark presence further increase the likelihood of such attacks. In this paper, we propose a secure DNN watermarking scheme named ChainMarks, which generates secure and robust watermarks by introducing a cryptographic chain into the trigger inputs and utilizes a two-phase Monte Carlo method for determining watermark presence. First, ChainMarks generates trigger inputs as a watermark dataset by repeatedly applying a hash function over a secret key, where the target labels associated with trigger inputs are generated from the digital signature of model owner. Then, the watermarked model is produced by training a DNN over both the original and watermark datasets. To verify watermarks, we compare the predicted labels of trigger inputs with the target labels and determine ownership with a more accurate decision threshold that considers the classification probability of specific models. Experimental results show that ChainMarks exhibits higher levels of robustness and security compared to state-of-the-art watermarking schemes. With a better marginal utility, ChainMarks provides a higher probability guarantee of watermark presence in DNN models with the same level of watermark accuracy.

模型水印密码学版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。