跳到主要导航 跳到搜索 跳到主要内容

A DLM watermarking method based on a spatiotemporal chaos with DNA computing

  • Dehui Wang
  • , Yingqian Zhang*
  • , Qiang Wei
  • , Yumei Xue
  • , Shuang Zhou
  • *此作品的通讯作者
  • Beihang University
  • Xiamen University
  • Beihua University
  • Chongqing Normal University

科研成果: 期刊稿件文章同行评审

摘要

Intellectual property (IP) protection for deep learning models (DLM) remains a hotspot, while the main solution is to give each model a universal and useful identity, which is analogous to the identification systems in human society. Recently, black-box watermarking technique has emerged as the primary option for IPP, however, small key space and fraudulent ownership claim attacks are still unresolved. In this paper, we proposed a black-box watermarking method based on a spatiotemporal chaos, Arnold Coupled Logistic Map Lattices (ACLML), with DNA permutation. Firstly, the ACLML can provide favorable chaotic properties to the trigger set and make it unpredictable against machine learning attacks and statistical inference. Secondly, the motion of the ACLML is controlled by particular parameters, which can provide a large key space and assign each model a unique identifier, meeting the commercialization needs of DLM. Thirdly, the trigger samples and chaotic values that build the trigger set are mutually independent, guaranteeing the security of the watermark. Theoretical analysis indicates that our scheme is secure and practical. We also compared it with the previous method, the experimental results demonstrate that our method shows better robustness against fine-tuning attacks and overwriting attacks. Moreover, it also effectively suppresses fraudulent ownership claim attacks.

源语言英语
文章编号130981
期刊Neurocomputing
652
DOI
出版状态已出版 - 1 11月 2025

指纹

探究 'A DLM watermarking method based on a spatiotemporal chaos with DNA computing' 的科研主题。它们共同构成独一无二的指纹。

引用此