The proliferation of Deep Neural Networks (DNN) in commercial applications is expanding rapidly. Simultaneously, the increasing complexity and cost of training DNN models have intensified the urgency surrounding the protection of intellectual property associated with these trained models. In this regard, DNN watermarking has emerged as a crucial safeguarding technique. This paper presents FedReverse, a novel multiparty reversible watermarking approach for robust copyright protection while minimizing performance impact. Unlike existing methods, FedReverse enables collaborative watermark embedding from multiple parties after model training, ensuring individual copyright claims. In addition, FedReverse is reversible, enabling complete watermark removal with unanimous client consent. FedReverse demonstrates perfect covering, ensuring that observations of watermarked content do not reveal any information about the hidden watermark. Additionally, it showcases resistance against Known Original Attacks (KOA), making it highly challenging for attackers to forge watermarks or infer the key. This paper further evaluates FedReverse through comprehensive simulations involving Multi-layer Perceptron (MLP) and Convolutional Neural Networks (CNN) trained on the MNIST dataset. The simulations demonstrate FedReverse's robustness, reversibility, and minimal impact on model accuracy across varying embedding parameters and multiple client scenarios.
翻译:深度神经网络在商业应用中的普及正迅速扩展。与此同时,训练DNN模型日益增长的复杂性和成本,加剧了保护这些训练模型相关知识产权的紧迫性。在此背景下,DNN水印技术已成为一项关键的保护手段。本文提出FedReverse,一种新颖的多方可逆水印方法,旨在实现鲁棒的版权保护,同时将性能影响降至最低。与现有方法不同,FedReverse允许在模型训练后由多方协作嵌入水印,确保各方的版权主张。此外,FedReverse具有可逆性,能在全体客户端一致同意下完全移除水印。FedReverse展现了完美的覆盖性,确保对含水印内容的观察不会泄露任何关于隐藏水印的信息。同时,它表现出对已知原始攻击的抵抗力,使得攻击者极难伪造水印或推断密钥。本文进一步通过在MNIST数据集上训练的多层感知器和卷积神经网络进行了全面模拟,以评估FedReverse。模拟结果表明,在不同的嵌入参数和多客户端场景下,FedReverse具有鲁棒性、可逆性,且对模型精度影响极小。