JOURNAL ARTICLE

Robust Watermarking for Deep Neural Networks via Bi-level Optimization

Peng YangYingjie LaoPing Li

Year: 2021 Journal:   2021 IEEE/CVF International Conference on Computer Vision (ICCV)

Abstract

Deep neural networks (DNNs) have become state-of-the-art in many application domains. The increasing complexity and cost for building these models demand means for protecting their intellectual property (IP). This paper presents a novel DNN framework that optimizes the robustness of the embedded watermarks. Our method is originated from DNN fault attacks. Different from prior end-to-end DNN watermarking approaches, we only modify a tiny subset of weights to embed the watermark, which also facilities better control of the model behaviors and enables larger rooms for optimizing the robustness of the watermarks.In this paper, built upon the above concept, we pro-pose a bi-level optimization framework where the inner loop phase optimizes the example-level problem to generate robust exemplars, while the outer loop phase proposes a masked adaptive optimization to achieve the robustness of the projected DNN models. Our method alternates the learning of the protected models and watermark exemplars across all phases, where watermark exemplars are not just data samples that could be optimized and adjusted instead. We verify the performance of the proposed methods over a wide range of datasets and DNN architectures. Various transformation attacks including fine-tuning, pruning and overwriting are used to evaluate the robustness.

Keywords:
Robustness (evolution) Digital watermarking Watermark Computer science Artificial intelligence Artificial neural network Deep neural networks Deep learning Machine learning Computer engineering Pattern recognition (psychology) Embedding Image (mathematics)

Metrics

45
Cited By
4.90
FWCI (Field Weighted Citation Impact)
58
Refs
0.97
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Advanced Neural Network Applications
Physical Sciences →  Computer Science →  Computer Vision and Pattern Recognition
Generative Adversarial Networks and Image Synthesis
Physical Sciences →  Computer Science →  Computer Vision and Pattern Recognition

Related Documents

BOOK-CHAPTER

Adaptive Robust Watermarking Method Based on Deep Neural Networks

Fan LiWan ChenFangjun Huang

Lecture notes in computer science Year: 2023 Pages: 162-173
JOURNAL ARTICLE

A Robust DCT-Based Scheme for Watermarking Deep Neural Networks

Mohammed BaziyadIbrahim KamelTamer RabieGrigory Kabatyansky

Journal:   Procedia Computer Science Year: 2024 Vol: 231 Pages: 397-402
JOURNAL ARTICLE

FingerMarks: Robust Multi-Bit Watermarking for Remote Deep Neural Networks

Qingguang LiGuangluan XuXiyu Qi

Journal:   Electronics Year: 2025 Vol: 14 (24)Pages: 4818-4818
JOURNAL ARTICLE

DICTION: DynamIC robusT whIte bOx Watermarking Scheme for Deep Neural Networks

Reda BellafqiraGouenou Coatrieux

Journal:   Applied Sciences Year: 2025 Vol: 15 (13)Pages: 7511-7511
© 2026 ScienceGate Book Chapters — All rights reserved.