As deep learning technology becomes increasingly prevalent, machine learning models, as valuable assets of enterprises, are facing the risk of model theft. Attackers can replicate the performance of original models without incurring high development costs by repeatedly querying APIs to collect labeled data and training functionally equivalent local models. Although existing model watermarking techniques can help developers verify model ownership, their high visibility makes them detectable and analysis, and even removal by attackers, posing significant security risks. To address these issues, we design DNN watermarking method called WatermarkMamba, which combines selective state-space models with image steganography to seamlessly embed secret images into carrier images, making the generated watermark images visually almost indistinguishable from the carrier images. By fine-tuning the model, it outputs the target labels when encountering a carrier containing the watermark, thereby realizing the ownership verification. Our method is resistant to pruning and counterattacks, effectively enhancing the stealth and robustness of the watermark. Multiple experimental results substantiate the efficacy of our WatermarkMamba steganography method in embedding and retrieving secret images into carriers with high. Furthermore, the stealthiness of our watermarking method enhances the security and practicality of model theft protection.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Utilizing WatermarkMamba to Conceal Watermarks for Effective Model Theft Protection

  • Yuwen Zhao,
  • Qi Zhong

摘要

As deep learning technology becomes increasingly prevalent, machine learning models, as valuable assets of enterprises, are facing the risk of model theft. Attackers can replicate the performance of original models without incurring high development costs by repeatedly querying APIs to collect labeled data and training functionally equivalent local models. Although existing model watermarking techniques can help developers verify model ownership, their high visibility makes them detectable and analysis, and even removal by attackers, posing significant security risks. To address these issues, we design DNN watermarking method called WatermarkMamba, which combines selective state-space models with image steganography to seamlessly embed secret images into carrier images, making the generated watermark images visually almost indistinguishable from the carrier images. By fine-tuning the model, it outputs the target labels when encountering a carrier containing the watermark, thereby realizing the ownership verification. Our method is resistant to pruning and counterattacks, effectively enhancing the stealth and robustness of the watermark. Multiple experimental results substantiate the efficacy of our WatermarkMamba steganography method in embedding and retrieving secret images into carriers with high. Furthermore, the stealthiness of our watermarking method enhances the security and practicality of model theft protection.