@inproceedings{a705d0ac5c32407db9fbdafb5ba0de10,
title = "Fragile Neural Network Watermarking with Trigger Image Set",
abstract = "Recent studies show that deep neural networks are vulnerable to data poisoning and backdoor attacks, both of which involve malicious fine tuning of deep models. In this paper, we first propose a black-box based fragile neural network watermarking method for the detection of malicious fine tuning. The watermarking process can be divided into three steps. Firstly, a set of trigger images is constructed based on a user-specific secret key. Then, a well trained DNN model is fine-tuned to classify the normal images in training set and trigger images in trigger set simultaneously in a two-stage alternate training manner. Fragile watermark is embedded by this means while keeping model{\textquoteright}s original classification ability. The watermarked model is sensitive to malicious fine tuning and will produce unstable classification results of the trigger images. At last, the integrity of the network model can be verified by analyzing the output of watermarked model with the trigger image set as input. The experiments on three benchmark datasets demonstrate that our proposed watermarking method is effective in detecting malicious fine tuning.",
keywords = "Backdoor defense, Data poisoning, Fragile watermarking, Malicious tuning detection, Model integrity protection, Neural network",
author = "Renjie Zhu and Ping Wei and Sheng Li and Zhaoxia Yin and Xinpeng Zhang and Zhenxing Qian",
note = "Publisher Copyright: {\textcopyright} 2021, Springer Nature Switzerland AG.; 14th International Conference on Knowledge Science, Engineering and Management, KSEM 2021 ; Conference date: 14-08-2021 Through 16-08-2021",
year = "2021",
doi = "10.1007/978-3-030-82136-4\_23",
language = "英语",
isbn = "9783030821357",
series = "Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)",
publisher = "Springer Science and Business Media Deutschland GmbH",
pages = "280--293",
editor = "Han Qiu and Cheng Zhang and Zongming Fei and Meikang Qiu and Sun-Yuan Kung",
booktitle = "Knowledge Science, Engineering and Management - 14th International Conference, KSEM 2021, Proceedings",
address = "德国",
}