Abstract
Intellectual property (IP) protection for deep learning models (DLM) remains a hotspot, while the main solution is to give each model a universal and useful identity, which is analogous to the identification systems in human society. Recently, black-box watermarking technique has emerged as the primary option for IPP, however, small key space and fraudulent ownership claim attacks are still unresolved. In this paper, we proposed a black-box watermarking method based on a spatiotemporal chaos, Arnold Coupled Logistic Map Lattices (ACLML), with DNA permutation. Firstly, the ACLML can provide favorable chaotic properties to the trigger set and make it unpredictable against machine learning attacks and statistical inference. Secondly, the motion of the ACLML is controlled by particular parameters, which can provide a large key space and assign each model a unique identifier, meeting the commercialization needs of DLM. Thirdly, the trigger samples and chaotic values that build the trigger set are mutually independent, guaranteeing the security of the watermark. Theoretical analysis indicates that our scheme is secure and practical. We also compared it with the previous method, the experimental results demonstrate that our method shows better robustness against fine-tuning attacks and overwriting attacks. Moreover, it also effectively suppresses fraudulent ownership claim attacks.
| Original language | English |
|---|---|
| Article number | 130981 |
| Journal | Neurocomputing |
| Volume | 652 |
| DOIs | |
| State | Published - 1 Nov 2025 |
Keywords
- Chaotic annotation
- DNA
- Deep learning
- Intellectual property protection
- Spatiotemporal chaos
- Watermarking
Fingerprint
Dive into the research topics of 'A DLM watermarking method based on a spatiotemporal chaos with DNA computing'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver