Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security 2021
DOI: 10.1145/3437880.3460402
|View full text |Cite
|
Sign up to set email alerts
|

White-Box Watermarking Scheme for Fully-Connected Layers in Fine-Tuning Model

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
13
0
1

Year Published

2022
2022
2024
2024

Publication Types

Select...
4
2
1

Relationship

1
6

Authors

Journals

citations
Cited by 11 publications
(14 citation statements)
references
References 4 publications
0
13
0
1
Order By: Relevance
“…These models were trained using more than 1,000,000 images from the ImageNet [ 37 ] database. A watermark was embedded into the fine-tuning model during training, similar to the experiments in [ 12 ].…”
Section: Resultsmentioning
confidence: 99%
See 2 more Smart Citations
“…These models were trained using more than 1,000,000 images from the ImageNet [ 37 ] database. A watermark was embedded into the fine-tuning model during training, similar to the experiments in [ 12 ].…”
Section: Resultsmentioning
confidence: 99%
“…For instance, the constraint given by Equation ( 5 ) can be applied to the embedding operations in [ 6 , 7 , 8 , 9 ]. In the case of the method presented in [ 12 ], the embedding operation based on the constraint can be regarded as the initial assignment of weight parameters to a DNN model, and the change in weights at each epoch is corrected by iteratively performing the operation.…”
Section: Proposed Dnn Watermarkingmentioning
confidence: 99%
See 1 more Smart Citation
“…We systematize the existing DNN watermarking schemes into parameter-embedding and data-poisoning watermarking schemes based on whether the owner needs to access the suspicious model in ownership verification. Parameter-embedding watermarking scheme embeds watermarks into the target model's parameters [18,38] or the activations of hidden layers [30,36]. Uchida et al [38] proposed embedding watermarks into the model parameters by using a parameter regularizer with a designed embedding loss.…”
Section: Related Work 21 Dnn Watermarkingmentioning
confidence: 99%
“…In general, the parameterembedding and data-poisoning are two mainstream watermarking schemes [6,14,25,45]. Noticeably, the parameter embedding watermarking scheme requires white-box access to the suspicious model which is not practical in the real-world scenario [18,42]. The data-poisoning watermarking scheme crafts a set of samplelabel pairs (also called verification samples) to enforce the DNN model memorizing them via carefully model fine-tuning.…”
Section: Introductionmentioning
confidence: 99%