Passer à la navigation principale Passer à la recherche Passer au contenu principal

A Hitchhiker's Guide to White-Box Neural Network Watermarking Robustness

  • Telecom Sudparis
  • Institut Polytechnique de Paris
  • University of Turin
  • University of Padova

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

The present study deals with white-box Neural Network (NN) watermarking and focuses on the robustness property. The first contribution consists of formalizing neuron permutation as a geometric attack, thus demonstrating the very existence of this class of attacks for NN watermarking. The second contribution consists in devising and demonstrating the effectiveness of the corresponding counter-attack. As a side result, the possibility of extending NN white-box watermarking scope beyond image classification is brought to light. The experimental study considers three state-of-the-art methods, four NN models, three tasks (image classification, segmentation, and video coding), and five types of attacks. We underline that none of the existing methods is robust against the geometric attack, and using the counter-attack advanced in this paper effectively ensures the robustness.

langue originaleAnglais
titre2023 11th European Workshop on Visual Information Processing, EUVIP 2023 - Proceedings
EditeurInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronique)9798350342185
Les DOIs
étatPublié - 1 janv. 2023
Evénement11th European Workshop on Visual Information Processing, EUVIP 2023 - Gjovik, Norvcge
Durée: 11 sept. 202314 sept. 2023

Série de publications

NomProceedings - European Workshop on Visual Information Processing, EUVIP
ISSN (imprimé)2471-8963

Une conférence

Une conférence11th European Workshop on Visual Information Processing, EUVIP 2023
Pays/TerritoireNorvcge
La villeGjovik
période11/09/2314/09/23

Empreinte digitale

Examiner les sujets de recherche de « A Hitchhiker's Guide to White-Box Neural Network Watermarking Robustness ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation