The invention discloses a revocable depth model watermarking method and
system, belongs to the technical field of
artificial intelligence model security, is provided for adapting to compliance and flexible requirements of a real industrial scene, and has the technical key points that smooth geometric disturbance is introduced into an intermediate feature space to generate a trigger sample; the original task and the watermarking behavior are restrained simultaneously by adopting joint loss; a
watermark sensitive channel is isolated from a normal reasoning channel through structured regularization and routing separation, and interference of watermarks on a main task is reduced; and in the
revocation stage, selective gating suppression is carried out on the triggering sensitive neurons, so that controllable, rapid and low-loss
watermark removal is realized. In the
verification stage, the
watermark success rate is calculated by adopting a secret trigger set to judge the watermark existence; in the
revocation stage, the WSR is reduced to be below a safety threshold value on the premise of keeping the model precision basically unchanged. Compared with an existing irreversible parameter-level or behavior-level watermark, the method has the advantages of
revocation, small residual trace, low influence on main task performance,
adaptation to common compression / fine adjustment scenes and the like, is suitable for application scenes such as model short-term
authorization, transfer transaction and multi-party cooperation, and can be expanded to various network structures and task types.