Exploiting Robust Model Watermarking Against the Model Fine-Tuning Attack via Flat Minima Aware Optimizers
Dongdong Lin, Yue Li, Bin Li, Jiwu Huang
Abstract
With the rapid advancement of deep neural networks (DNNs), model watermarking has emerged as a widely adopted technique for safeguarding model copyrights. A prevalent method involves utilizing a watermark decoder to retrieve watermark bits from generated outputs, but such methods are often vulnerable to model fine-tuning attacks. Traditionally, this challenge is mitigated through adversarial training or data augmentation, both of which significantly increase the computational burden. In this paper, we present a solution employing Flat Minima Aware (FMA) optimizers to bolster the robustness of model watermarking without requiring additional training data. By optimizing the watermark loss with flat minima awareness, our approaches significantly enhance the robustness of watermarks against the model fine-tuning attack. Comprehensive experiments have demonstrated our method’s superior ability to preserve watermark integrity. These findings suggest that this innovative optimization strategy offers a robust and efficient pathway for protecting models, thereby contributing to more secure and reliable model copyright protection mechanisms.
BibTeX
@inproceedings{icassp2025_exploitingrobust,
title = {Exploiting Robust Model Watermarking Against the Model Fine-Tuning Attack via Flat Minima Aware Optimizers},
author = {Dongdong Lin and Yue Li and Bin Li and Jiwu Huang},
booktitle = {ICASSP 2025},
year = {2025}
}