Protecting deep learning models using watermarking

Patent №

US 11,163,860

Granted

2021-11-02

Filed 2018

Owner

INTERNATIONAL BUSINESS MACHINES CORPORATION

AI components

4

ml · vision · kr · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

15997159

A framework to accurately and quickly verify the ownership of remotely-deployed deep learning models is provided without affecting model accuracy for normal input data. The approach involves generating a watermark, embedding the watermark in a local deep neural network (DNN) model by learning, namely, by training the local DNN model to learn the watermark and a predefined label associated therewith, and later performing a black-box verification against a remote service that is suspected of executing the DNN model without permission. The predefined label is distinct from a true label for a data item in training data for the model that does not include the watermark. Black-box verification includes simply issuing a query that includes a data item with the watermark, and then determining whether the query returns the predefined label.

Machine learningVisionKnowledge representationAI hardwareG06F 21/16G06N 3/044G06N 3/0464G06N 3/048G06N 3/08G06N 3/084G06N 3/09G06N 3/045

AI classification

Machine learning1.00
AI hardware1.00
Knowledge representation0.98
Vision0.98
Natural language0.06
Planning0.03
Evolutionary computation0.00
Speech0.00

Ownership

INTERNATIONAL BUSINESS MACHINES CORPORATION

assignment · 459800930

Assignors

GU, ZHONGSHU, HUANG, HEQING, STOECKLIN, MARC PHILIPPE, ZHANG, JIALONG

On an employer assignment, the assignors are typically the inventors.

From the same owner

© 2026 NYSGPT2525 LLC