This work proposes a novel lattice quantization-based backdoor watermarking framework for DNNs in black-box settings that embeds the owner’s identity into trigger samples via lattice quantization index modulation, achieving identity encoding while maintaining trigger imperceptibility.
Abstract
With the increasing trend of open-sourcing deep neural network (DNN) models, protecting model ownership has become a critical challenge, particularly in high-stakes domains such as medical AI. Existing backdoor-based watermarking methods suffer from two key limitations: visible trigger patterns and the lack of a reliable linkage to the model owner’s identity. In addition, many current verification schemes are often simplistic, relying mainly on task accuracy over trigger sets. To address these issues, we propose a novel lattice quantization-based backdoor watermarking framework for DNNs in black-box settings. The proposed method embeds the owner’s identity into trigger samples via lattice quantization index modulation, achieving identity encoding while maintaining trigger imperceptibility. Furthermore, we introduce an enhanced verification strategy that combines task performance with statistical identity extraction, providing more reliable ownership verification. Extensive experiments on benchmark datasets and multiple DNN architectures demonstrate that the proposed method achieves nearly 100% watermark success rate (WSR) and over 91% identity extraction success rate (ESR), with benign accuracy degradation below 1.51%, validating its effectiveness for reliable DNN ownership verification in black-box settings.
FakeMark is presented, a gradient-guided false-claim attack for image classifiers that uses a white-box surrogate but never queries or accesses the victim model during attack construction, to motivate provenance-aware, multi-factor ownership protocols.
Yu-Tong Wu, Wen-Yue Li, He-Wang Nie et al.· Cybersecurity· 0 citations
A dual-path network is proposed to encode watermark information into both the generated image and the owner’s secret key, which achieves superior robustness against various adversarial attacks while maintaining high visual quality across diverse generative models.
Cong-Rong Li, Ling-Yun Yu, Pei-Qi Jiang et al.· Proceedings of the Thirty-Fi...· 0 citations
Image watermarking supports provenance and attribution by embedding verifiable identity information into images. Practical deployments, however, must jointly satisfy requirements for attack resistance, false-positive rate (FPR), image quality, and latency. Existing watermarking methods are robust to different classes o...
Mingzhe Li, Yue-Feng Peng, Kejing Xia et al.· 0 citations
Model watermarking is a commonly used ownership verification technique for protecting the copyright of deep learning models. However, in practically deployed black-box model service scenarios, existing methods typically rely on misclassification-based backdoor trigger mechanisms, or assume that the verifier can obtain...
Jing Xiao, Song Xiao, Chao Guo et al.· Journal of King Saud Univers...· 0 citations
FeatMark is introduced, a watermarking framework that shifts from pixel-level, energy-starved perturbations to inconspicuous semantic features: small, scene-consistent micro- features that remain natural to humans while providing a stronger, machine-verifiable provenance signal.
Hao-Yang Li, Ruo-Xi Sun, Qing-Qing Ye et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.