Skip to content
Open access

Lattice-Quantization Identity Watermarking for Deep Neural Network Ownership Protection

2026 · IEEE Access · Vol 14, pp. 135993-136008 · 0 citations · 61 references

TL;DR

This work proposes a novel lattice quantization-based backdoor watermarking framework for DNNs in black-box settings that embeds the owner’s identity into trigger samples via lattice quantization index modulation, achieving identity encoding while maintaining trigger imperceptibility.

Abstract

With the increasing trend of open-sourcing deep neural network (DNN) models, protecting model ownership has become a critical challenge, particularly in high-stakes domains such as medical AI. Existing backdoor-based watermarking methods suffer from two key limitations: visible trigger patterns and the lack of a reliable linkage to the model owner’s identity. In addition, many current verification schemes are often simplistic, relying mainly on task accuracy over trigger sets. To address these issues, we propose a novel lattice quantization-based backdoor watermarking framework for DNNs in black-box settings. The proposed method embeds the owner’s identity into trigger samples via lattice quantization index modulation, achieving identity encoding while maintaining trigger imperceptibility. Furthermore, we introduce an enhanced verification strategy that combines task performance with statistical identity extraction, providing more reliable ownership verification. Extensive experiments on benchmark datasets and multiple DNN architectures demonstrate that the proposed method achieves nearly 100% watermark success rate (WSR) and over 91% identity extraction success rate (ESR), with benign accuracy degradation below 1.51%, validating its effectiveness for reliable DNN ownership verification in black-box settings.

Read PDF

Similar papers

Open access Sep 2026

FakeMark: gradient-guided false watermark claims via robust feature fusion

FakeMark is presented, a gradient-guided false-claim attack for image classifiers that uses a white-box surrogate but never queries or accesses the victim model during attack construction, to motivate provenance-aware, multi-factor ownership protocols.

Yu-Tong Wu, Wen-Yue Li, He-Wang Nie et al. · 0 citations
Conference Open access Sep 2026

Latents-Inv:Robust Semantic Watermark via Dual-Path Mutual Information Redundancy for Diffusion Models

A dual-path network is proposed to encode watermark information into both the generated image and the owner’s secret key, which achieves superior robustness against various adversarial attacks while maintaining high visual quality across diverse generative models.

Cong-Rong Li, Ling-Yun Yu, Pei-Qi Jiang et al. · 0 citations
Preprint Sep 2026

Made to Measure: Designing Image Watermarks to Specification

Image watermarking supports provenance and attribution by embedding verifiable identity information into images. Practical deployments, however, must jointly satisfy requirements for attack resistance, false-positive rate (FPR), image quality, and latency. Existing watermarking methods are robust to different classes o...

Mingzhe Li, Yue-Feng Peng, Kejing Xia et al. · 0 citations
Open access Aug 2026

Backdoor-free model watermarking via differential verification of adversarial samples and multi-bit information extraction

Model watermarking is a commonly used ownership verification technique for protecting the copyright of deep learning models. However, in practically deployed black-box model service scenarios, existing methods typically rely on misclassification-based backdoor trigger mechanisms, or assume that the verifier can obtain...

Jing Xiao, Song Xiao, Chao Guo et al. · 0 citations
Preprint Sep 2026

FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models

FeatMark is introduced, a watermarking framework that shifts from pixel-level, energy-starved perturbations to inconspicuous semantic features: small, scene-consistent micro- features that remain natural to humans while providing a stronger, machine-verifiable provenance signal.

Hao-Yang Li, Ruo-Xi Sun, Qing-Qing Ye et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.