Deep Neural Networks have recently gained lots of success after enabling\nseveral breakthroughs in notoriously challenging problems. Training these\nnetworks is computationally expensive and requires vast amounts of training\ndata. Selling such pre-trained models can, therefore, be a lucrative business\nmodel. Unfortunately, once the models are sold they can be easily copied and\nredistributed. To avoid this, a tracking mechanism to identify models as the\nintellectual property of a particular vendor is necessary.\n In this work, we present an approach for watermarking Deep Neural Networks in\na black-box way. Our scheme works for general classification tasks and can\neasily be combined with current learning algorithms. We show experimentally\nthat such a watermark has no noticeable impact on the primary task that the\nmodel is designed for and evaluate the robustness of our proposal against a\nmultitude of practical attacks. Moreover, we provide a theoretical analysis,\nrelating our approach to previous work on backdooring.\n
Paper
References (53)
Scroll for more · 38 remaining