TY - JOUR
T1 - A DLM watermarking method based on a spatiotemporal chaos with DNA computing
AU - Wang, Dehui
AU - Zhang, Yingqian
AU - Wei, Qiang
AU - Xue, Yumei
AU - Zhou, Shuang
N1 - Publisher Copyright:
© 2025 Elsevier B.V.
PY - 2025/11/1
Y1 - 2025/11/1
N2 - Intellectual property (IP) protection for deep learning models (DLM) remains a hotspot, while the main solution is to give each model a universal and useful identity, which is analogous to the identification systems in human society. Recently, black-box watermarking technique has emerged as the primary option for IPP, however, small key space and fraudulent ownership claim attacks are still unresolved. In this paper, we proposed a black-box watermarking method based on a spatiotemporal chaos, Arnold Coupled Logistic Map Lattices (ACLML), with DNA permutation. Firstly, the ACLML can provide favorable chaotic properties to the trigger set and make it unpredictable against machine learning attacks and statistical inference. Secondly, the motion of the ACLML is controlled by particular parameters, which can provide a large key space and assign each model a unique identifier, meeting the commercialization needs of DLM. Thirdly, the trigger samples and chaotic values that build the trigger set are mutually independent, guaranteeing the security of the watermark. Theoretical analysis indicates that our scheme is secure and practical. We also compared it with the previous method, the experimental results demonstrate that our method shows better robustness against fine-tuning attacks and overwriting attacks. Moreover, it also effectively suppresses fraudulent ownership claim attacks.
AB - Intellectual property (IP) protection for deep learning models (DLM) remains a hotspot, while the main solution is to give each model a universal and useful identity, which is analogous to the identification systems in human society. Recently, black-box watermarking technique has emerged as the primary option for IPP, however, small key space and fraudulent ownership claim attacks are still unresolved. In this paper, we proposed a black-box watermarking method based on a spatiotemporal chaos, Arnold Coupled Logistic Map Lattices (ACLML), with DNA permutation. Firstly, the ACLML can provide favorable chaotic properties to the trigger set and make it unpredictable against machine learning attacks and statistical inference. Secondly, the motion of the ACLML is controlled by particular parameters, which can provide a large key space and assign each model a unique identifier, meeting the commercialization needs of DLM. Thirdly, the trigger samples and chaotic values that build the trigger set are mutually independent, guaranteeing the security of the watermark. Theoretical analysis indicates that our scheme is secure and practical. We also compared it with the previous method, the experimental results demonstrate that our method shows better robustness against fine-tuning attacks and overwriting attacks. Moreover, it also effectively suppresses fraudulent ownership claim attacks.
KW - Chaotic annotation
KW - DNA
KW - Deep learning
KW - Intellectual property protection
KW - Spatiotemporal chaos
KW - Watermarking
UR - https://www.scopus.com/pages/publications/105011538096
U2 - 10.1016/j.neucom.2025.130981
DO - 10.1016/j.neucom.2025.130981
M3 - 文章
AN - SCOPUS:105011538096
SN - 0925-2312
VL - 652
JO - Neurocomputing
JF - Neurocomputing
M1 - 130981
ER -