水印
数字水印
计算机科学
后门
钥匙(锁)
解码
人工神经网络
可扩展性
编码(内存)
签名(拓扑)
人工智能
仿制品
路径(计算)
数据挖掘
传输(计算)
公钥密码术
数字签名
特征(语言学)
计算机安全
稳健性(进化)
解码方法
理论计算机科学
机器学习
偏移量(计算机科学)
实时计算
作者
Hewang Nie,Xuemei Yuan,Jue Xiao
标识
DOI:10.1109/tcsvt.2026.3651461
摘要
Neural-network model trading raises two unmet requirements for watermarking: exclusive ownership verification and updateability (transfer/revoke) without retraining. We present a training-time framework that jointly embeds a keydriven dynamic label-mapping and a proactive, self-defending trigger. The label-mapping encodes an owner-specific signature that authorized key holders can verify, update, or transfer by rotating keys; the defensive trigger actively hardens the model against unauthorized backdoor insertion and fakewatermark attempts. Our design yields three properties: (i) exclusivity—only the correct key decodes the watermark; (ii) updateability—ownership can be changed without retraining the backbone; and (iii) robustness—the watermark persists under common post-deployment changes. Across CIFAR-10/100, GTSRB, and Tiny ImageNet on five architectures, the method achieves (> 97%) watermark success rate while preserving original accuracy within 0.5 percentage points, retains (>85%) watermark strength after fine-tuning and (60%) pruning, and reduces fake-watermark success to (< 1.5%) (vs. (> 95%) on unprotected models). By coupling updateable encoding with proactive defense, our approach offers a practical, scalable path to secure, transferable ownership verification for neural-network marketplaces and model exchanges.
科研通智能强力驱动
Strongly Powered by AbleSci AI