跳到主要导航 跳到搜索 跳到主要内容

Fragile Neural Network Watermarking with Trigger Image Set

  • Renjie Zhu
  • , Ping Wei
  • , Sheng Li
  • , Zhaoxia Yin
  • , Xinpeng Zhang*
  • , Zhenxing Qian
  • *此作品的通讯作者
  • Fudan University
  • School of Computer Science and Technology, Anhui University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Recent studies show that deep neural networks are vulnerable to data poisoning and backdoor attacks, both of which involve malicious fine tuning of deep models. In this paper, we first propose a black-box based fragile neural network watermarking method for the detection of malicious fine tuning. The watermarking process can be divided into three steps. Firstly, a set of trigger images is constructed based on a user-specific secret key. Then, a well trained DNN model is fine-tuned to classify the normal images in training set and trigger images in trigger set simultaneously in a two-stage alternate training manner. Fragile watermark is embedded by this means while keeping model’s original classification ability. The watermarked model is sensitive to malicious fine tuning and will produce unstable classification results of the trigger images. At last, the integrity of the network model can be verified by analyzing the output of watermarked model with the trigger image set as input. The experiments on three benchmark datasets demonstrate that our proposed watermarking method is effective in detecting malicious fine tuning.

源语言英语
主期刊名Knowledge Science, Engineering and Management - 14th International Conference, KSEM 2021, Proceedings
编辑Han Qiu, Cheng Zhang, Zongming Fei, Meikang Qiu, Sun-Yuan Kung
出版商Springer Science and Business Media Deutschland GmbH
280-293
页数14
ISBN(印刷版)9783030821357
DOI
出版状态已出版 - 2021
已对外发布
活动14th International Conference on Knowledge Science, Engineering and Management, KSEM 2021 - Tokyo, 日本
期限: 14 8月 202116 8月 2021

丛书

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
12815 LNAI
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议14th International Conference on Knowledge Science, Engineering and Management, KSEM 2021
国家/地区日本
Tokyo
时期14/08/2116/08/21

学术指纹

探究 'Fragile Neural Network Watermarking with Trigger Image Set' 的科研主题。它们共同构成独一无二的学术指纹。

引用此