ICASSP 2024accepted0 citations

Data-Free Watermark for Deep Neural Networks by Truncated Adversarial Distillation

Chao-Bo Yan, Fang-Qi Li, Shi-Lin Wang

Abstract

Model watermarking secures ownership verification and copyright protection of deep neural networks. In the black-box scenario, watermarking schemes commonly rely on injecting triggers and requiring the model's training data to maintain its performance. However, such knowledge might be unavailable in commercial settings as model transactions or copyright transfers. To tackle this challenge, we propose a novel data-free black-box watermarking scheme. Our approach modifies data-free adversarial distillation to efficiently obtain a generator that produces samples serving as a substitute for the training data so the watermark can achieve high fidelity without referring to the training data.

BibTeX
@inproceedings{icassp2024_datafreewatermar,
  title = {Data-Free Watermark for Deep Neural Networks by Truncated Adversarial Distillation},
  author = {Chao-Bo Yan and Fang-Qi Li and Shi-Lin Wang},
  booktitle = {ICASSP 2024},
  year = {2024}
}