Abstract: Deep neural networks (DNNs) have become an important tool for gaining understanding from mobile and embedded devices. The logically extensive preparation, sharing, and potential development of DNN models result in a compelling need for intellectual property (IP) protection. DNN watermarking has recently gained traction as a potential IP protection method. Existing DNN watermarking structures either fail to satisfy the discovery requirement or are vulnerable to many types of attacks, making enabling DNN watermarking on deployed devices in an extremely difficult task. We propose a watermarking method that incorporates the creator’s mark into the DNN-instruction strategy. While functioning normally in most situations, the resultant watermarked DNN behaves in an unexpected way when given any marked inputs, revealing the source. We’ll go through the system’s model execution on popular image grouping datasets in general, and demonstrate how robust watermarks will be incorporated into the models.
P.Ramesh
Analysis, Deep neural networks (DNNs), watermarking, embedded systems.
