TY - JOUR
T1 - A simultaneous dual watermarking scheme for deep learning models
AU - Wang, Dehui
AU - Zhang, Yingqian
AU - Zhou, Shuang
AU - Xue, Yumei
N1 - Publisher Copyright:
© 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.
PY - 2026/10
Y1 - 2026/10
N2 - Watermarking technology has become the prime approach for protecting intellectual property (IP) rights of deep learning models (DLM). However, the existing methods only focus on the single watermark format, which cannot simultaneously protect the IP rights of both buyers (users) and sellers (developers). After the model has been redistributed or customized, if the traded model only contains the seller’s watermark, the buyer cannot prove their ownership of the model. Conversely, if the model only contains the buyer’s watermark, it is difficult to trace its source when the model is stolen or illegally distributed. Therefore, we proposed a simultaneous dual watermarking scheme. Dual watermarks consist of two different trigger sets. Two trigger sets and original datasets are used together as the training set. In particular, the features among the three datasets exhibit a perpendicular relationship. Therefore, this relationship will not affect the model performance. In the proposed scheme, the two trigger sets are constructed by annotation with different chaotic sequences. Due to the sensitivity to the initial value, unpredictability, and non-periodicity of chaos, different initial values produce significantly different chaotic sequences. It guarantees a vertical relationship between features of the three dataset. Statistical analysis indicates that the watermark does not affect the decision boundaries of the DLM and does not show significant statistical characteristics. The experimental results indicate that, compared to other methods, the proposed scheme has superior effectiveness, fidelity, integrity, and robustness against fine-tuning attacks, overwriting attacks, and fraudulent ownership claim attacks.
AB - Watermarking technology has become the prime approach for protecting intellectual property (IP) rights of deep learning models (DLM). However, the existing methods only focus on the single watermark format, which cannot simultaneously protect the IP rights of both buyers (users) and sellers (developers). After the model has been redistributed or customized, if the traded model only contains the seller’s watermark, the buyer cannot prove their ownership of the model. Conversely, if the model only contains the buyer’s watermark, it is difficult to trace its source when the model is stolen or illegally distributed. Therefore, we proposed a simultaneous dual watermarking scheme. Dual watermarks consist of two different trigger sets. Two trigger sets and original datasets are used together as the training set. In particular, the features among the three datasets exhibit a perpendicular relationship. Therefore, this relationship will not affect the model performance. In the proposed scheme, the two trigger sets are constructed by annotation with different chaotic sequences. Due to the sensitivity to the initial value, unpredictability, and non-periodicity of chaos, different initial values produce significantly different chaotic sequences. It guarantees a vertical relationship between features of the three dataset. Statistical analysis indicates that the watermark does not affect the decision boundaries of the DLM and does not show significant statistical characteristics. The experimental results indicate that, compared to other methods, the proposed scheme has superior effectiveness, fidelity, integrity, and robustness against fine-tuning attacks, overwriting attacks, and fraudulent ownership claim attacks.
KW - Chaos
KW - Deep learning model
KW - Dual watermarking
KW - Intellectual property protection
KW - Ownership verification
UR - https://www.scopus.com/pages/publications/105038720437
U2 - 10.1016/j.neunet.2026.109089
DO - 10.1016/j.neunet.2026.109089
M3 - 文章
AN - SCOPUS:105038720437
SN - 0893-6080
VL - 202
JO - Neural Networks
JF - Neural Networks
M1 - 109089
ER -