|
This article is cited in 1 scientific paper (total in 1 paper)
IMAGE PROCESSING, PATTERN RECOGNITION
Method for copyright protection of deep neural networks using digital watermarking
Yu. D. Vybornova Samara National Research University
Abstract:
The article proposes a new method of copyright protection for deep neural networks. The main idea of the method is to embed digital watermarks into the protected model by retraining it on a unique set of pseudo-holographic images (pseudo-holograms). A pseudo-hologram is a two-dimensional sinusoidal signal that encodes a binary sequence of arbitrary length. By changing the phase of each sinusoid, it is possible to form various pseudo-hologram images based on a single bit sequence. The proposed approach to embedding is to generate a training sample in such a way that pseudo-holograms formed on the basis of one sequence fall into the same class. In this case, each class will correspond to different bit sequences. Verification of the digital watermark is carried out by applying various pseudo-holograms to the input of the model and checking whether the hidden sequence corresponds to a certain class. Experimental studies confirm the efficiency of the method and its compliance with all quality criteria established for the methods of neural network watermarking.
Keywords:
copyright protection, digital watermarking, deep neural networks, pseudo-holographic image
Received: 15.07.2022 Accepted: 23.10.2022
Citation:
Yu. D. Vybornova, “Method for copyright protection of deep neural networks using digital watermarking”, Computer Optics, 47:2 (2023), 251–261
Linking options:
https://www.mathnet.ru/eng/co1124 https://www.mathnet.ru/eng/co/v47/i2/p251
|
Statistics & downloads: |
Abstract page: | 22 | Full-text PDF : | 20 | References: | 15 |
|