The present study deals with white-box Neural Network (NN) watermarking and focuses on the robustness property. The first contribution consists of formalizing neuron permutation as a geometric attack, thus demonstrating the very existence of this class of attacks for NN watermarking. The second contribution consists in devising and demonstrating the effectiveness of the corresponding counter-attack. As a side result, the possibility of extending NN white-box watermarking scope beyond image classification is brought to light. The experimental study considers three state-of-the-art methods, four NN models, three tasks (image classification, segmentation, and video coding), and five types of attacks. We underline that none of the existing methods is robust against the geometric attack, and using the counter-attack advanced in this paper effectively ensures the robustness.

A Hitchhiker's Guide to White-Box Neural Network Watermarking Robustness

Mitrea M.;Tartaglione E.;Fiandrotti A.;Chaudhuri S.
2023-01-01

Abstract

The present study deals with white-box Neural Network (NN) watermarking and focuses on the robustness property. The first contribution consists of formalizing neuron permutation as a geometric attack, thus demonstrating the very existence of this class of attacks for NN watermarking. The second contribution consists in devising and demonstrating the effectiveness of the corresponding counter-attack. As a side result, the possibility of extending NN white-box watermarking scope beyond image classification is brought to light. The experimental study considers three state-of-the-art methods, four NN models, three tasks (image classification, segmentation, and video coding), and five types of attacks. We underline that none of the existing methods is robust against the geometric attack, and using the counter-attack advanced in this paper effectively ensures the robustness.
2023
11th European Workshop on Visual Information Processing, EUVIP 2023
Gjøvik
2023
Proceedings - European Workshop on Visual Information Processing, EUVIP
Institute of Electrical and Electronics Engineers Inc.
1
6
counter-attack; geometric attacks; neural network; robustness; watermarking; white-box
De Sousa Trias C.; Mitrea M.; Tartaglione E.; Fiandrotti A.; Cagnazzo M.; Chaudhuri S.
File in questo prodotto:
File Dimensione Formato  
Carl hitchhiker EUVIP23_permutation_watermark.pdf

Accesso aperto

Dimensione 925.43 kB
Formato Adobe PDF
925.43 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2318/2037890
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? ND
social impact