Watermark adding method, device, electronic device and storage medium
By embedding watermarks in the neural network model, the problem of adding watermarks in the existing technology affecting the accuracy of the model is solved, and watermarks are added to the neural network model without damaging the model performance.
Patent Information
- Application Number
- CN202011112978.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-16
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2040-10-16
AI Technical Summary
When adding watermarks to neural network models, the prior art can easily affect the calculation accuracy and performance of the model.
By determining the N numerical values contained in the digits of the first key, positioning N first weights in the neural network model, and embeding the second key as a watermark into the model, the specific method is to replace the value on each digit in the first key with the second value on the set digit of the corresponding first weight.
It is implemented to add watermarks to the model without affecting the calculation accuracy of the neural network model, avoiding the negative impact on the model performance.
Smart Images

Figure CN114387146B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of encryption technology, and in particular to a watermark adding method, device, electronic device and storage medium. Background Art
[0002] Neural network technology plays a vital role in the field of machine vision. Training a neural network model with excellent performance often requires a large number of high-quality image samples and a high-performance graphics processing unit (GPU) computing cluster. Therefore, in order to ensure that the trained neural network model is not copied, redistributed or illegally used, a watermark can be added to the neural network model. In related technologies, adding a watermark to the neural network will have a negative impact on the performance of the neural network. Summary of the invention
[0003] To solve related technical problems, the embodiments of the present application provide a watermark adding method, device, electronic device and storage medium.
[0004] The technical solution of the embodiment of the present application is implemented as follows:
[0005] The present application embodiment provides a watermark adding method, including:
[0006] Determine N first values included in all digits of the first key, where N is an integer greater than or equal to 1;
[0007] Locating N first weights in the neural network model; each of the N first weights corresponds to a first value among the N values;
[0008] The second key is embedded into the neural network model as a watermark; wherein,
[0009] The second key is obtained by replacing the first value of each digit in the first key with the second value of the corresponding first weight at the first set digit.
[0010] Wherein, in the above scheme, embedding the second key as a watermark into the neural network model includes:
[0011] The second key is embedded into at least one second weight of the neural network model.
[0012] In the above solution, when the second key is embedded into at least one second weight of the neural network model, the method includes:
[0013] All digits after the second set digit in the second weight are replaced by the second key.
[0014] In the above scheme, the second set digit includes a percentile.
[0015] In the above solution, the step of replacing all digits after the second set digit in the second weight with the second key includes:
[0016] During the training process of the neural network model, all digits after the second set digit in the second weight are replaced with the second key;
[0017] Wherein, the second set digit includes tens digit or ones digit.
[0018] In the above scheme, the method further includes:
[0019] The first key is randomly generated, the digital length of which is greater than a first set value.
[0020] In the above scheme, the method further includes:
[0021] The first key is generated based on the digital code corresponding to each character in the set character string.
[0022] The present application also provides a watermark adding device, including:
[0023] A determination unit, configured to determine N first values included in all digits of the first key; wherein N is an integer greater than or equal to 1;
[0024] A positioning unit, used for positioning N first weights in the neural network model; each first weight in the N first weights corresponds to a first value in the N values;
[0025] An embedding unit, used to embed the second key as a watermark into the neural network model; wherein,
[0026] The second key is obtained by replacing the first value of each digit in the first key with the second value of the corresponding first weight at the first set digit.
[0027] The embodiment of the present application also provides an electronic device, comprising: a first processor and a first communication interface; wherein,
[0028] The first processor is used to determine N first values included in all digits of the first key; locate N weights in the neural network model; embed the second key as a watermark into the neural network model; wherein,
[0029] N is an integer greater than or equal to 1; each of the N first weights corresponds to a first value among the N values; the second key is obtained by replacing the first value on each digit in the first key with the second value of the corresponding first weight on the first set digit.
[0030] An embodiment of the present application further provides an electronic device, comprising: a first processor and a first memory for storing a computer program that can be run on the processor,
[0031] Wherein, the first processor is used to execute the steps of any of the above-mentioned watermark adding methods when running the computer program.
[0032] The embodiment of the present application further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned watermark adding methods are implemented.
[0033] The watermarking method, device, electronic device and storage medium provided in the embodiments of the present application determine the N first numerical values included in all digits of the first key, locate N first weights in the neural network model, and each of the N first weights corresponds to a first numerical value of the N numerical values, and obtain the second key by replacing the first numerical value on each digit in the first key with the second numerical value of the corresponding first weight on the set digit, and embed the second key as a watermark in the neural network model. Here, the watermarking of the neural network model is achieved based on the weights in the neural network model, which avoids the influence on the calculation accuracy of the model caused by adjusting or expanding the training data in the related art to complete the watermarking, thereby ensuring the calculation accuracy of the neural network model and avoiding negative impact on the performance of the neural network model. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 This is a schematic diagram of the process of adding watermarks according to an embodiment of the present application;
[0035] Figure 2 This is an example diagram of the weights of the watermark embedded neural network model in the embodiment of the present application;
[0036] Figure 3 A schematic diagram of the structure of a watermark adding device implemented in this application;
[0037] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0038] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments.
[0039] Neural network technology has outstanding performance in image classification, target detection, semantic segmentation, etc., and plays a vital role in fields such as machine vision. Training a neural network model with excellent performance often requires a large number of high-quality image samples and a high-performance GPU computing cluster. Therefore, in order to ensure that the trained neural network model is not copied, redistributed or illegally used, the neural network model can be watermarked or encrypted.
[0040] In the related art, the technical means for encrypting the neural network model are as follows: by constructing various mapping functions, the weights of the neural network model are encoded by the function and stored, and when the model is used, the corresponding inverse function transformation is used to decode the stored values to obtain the weights of the neural network model, and then participate in the calculation. In this way, each time the neural network model is called, the corresponding weights need to be obtained by decoding, and the decoding process will consume a lot of time, affecting the processing efficiency of the neural network model. In addition, the neural network model can also be watermarked by embedding a watermark in the training data of the neural network model. However, after the training data is embedded with the watermark, the training data is adjusted and expanded, and the original distribution form of the training data is changed, resulting in a decrease in the calculation accuracy of the neural network model trained based on the training data embedded with the watermark, and the performance of the neural network model is poor. Alternatively, the neural network model is watermarked by directly adding a watermark "label" to the neural network model. However, this method is easy for others to recognize that the neural network model has been watermarked, and it is also easy to remove the watermark from the neural network model, and it is impossible to ensure that the neural network model is not copied, redistributed or illegally used.
[0041] Based on this, in various embodiments of the present application, the N first values included in all digits of the first key are determined, N first weights are located in the neural network model, and each of the N first weights corresponds to a first value of the N values, and the second key is obtained by replacing the first value on each digit in the first key with the second value of the corresponding first weight on the set digit, and the second key is embedded in the neural network model as a watermark. Here, there is no need to adjust and expand the training data of the neural network model, but to add a watermark to the neural network model based on the weights in the neural network model, which ensures the calculation accuracy of the neural network model and avoids negative impact on the performance of the neural network model.
[0042] The present application embodiment provides a watermark adding method, such as Figure 1 As shown, the method includes:
[0043] Step 101: Determine N first values included in all digits of a first key.
[0044] Wherein, N is an integer greater than or equal to 1.
[0045] Here, the first key is the original watermark content of the neural network model, which is composed of a certain length of digits, and each digit takes a corresponding value. Since for a single digit, the value that can be obtained in each digit is one of the value set {0,1,2,3,4,5,6,7,8,9}, all the digits of the first key include at least one value and at most 10 values.
[0046] Regarding the generation of the first key, in one embodiment, the method further includes:
[0047] The first key is randomly generated, the digital length of which is greater than a first set value.
[0048] Here, a random number with a sufficiently long digit generated randomly can be used as the first key, and the length of the digit can be set by the technician. Taking the weight of a deep neural network as an example, it is usually set to a floating point (float) 32 format. Based on this, in this embodiment, the digit length of the first key can be set with reference to the digit length after the decimal point of the weight, for example, the digit length of the first key is set to be 2 less than the digit length after the decimal point of the weight.
[0049] In addition, the first key can also be generated based on a string. Based on this, in one embodiment, the method further includes:
[0050] The first key is generated based on the digital code corresponding to each character in the set character string.
[0051] Here, the digital code corresponding to each character is set in a predefined character code table, where each character can correspond to a multi-bit code. In this way, the digital code corresponding to each character in the set string is found from the character code table, and the found digital codes are arranged in sequence according to the order of each character in the set string to generate the first key. For example, the digital code corresponding to each character in the string "China Mobile Communications Co., Ltd. Research Institute" is searched in sequence in the character code table to obtain the first key:
[0052] “20013222693122721160368902044926377384802084421496307403135038498”.
[0053] Step 102: Locate N first weights in the neural network model.
[0054] Each of the N first weights corresponds to a first value among the N values.
[0055] Here, according to the number N of numerical values involved in all digits of the first key, N first weights are located in the neural network model, and each of the located N first weights corresponds to one of the N numerical values.
[0056] See also Figure 2 For example, locate 5 weights in the hidden layers of the neural network model. Figure 2 Neuron 1 in is the position of the first weight located.
[0057] Step 103: Embed the second key as a watermark into the neural network model.
[0058] The second key is obtained by replacing the first value on each digit in the first key with the second value of the corresponding first weight on the first set digit.
[0059] For example, take pi as the first key, and record the non-zero values of pi as pi1, pi2, etc., where pi i ∈{1,2,3,4,5,6,7,8,9}, i≤9. Locate 9 first weights in the neural network model M, and sort the located first weights, denoted as w1, w2, etc., and select any one of the 9 first weights w j (j≤9) corresponds to π i , for example, π = 3.1415926..., let w1 correspond to 3, w2 correspond to 1..., when the weights are stored in a float 32-bit data structure, w j There are at least 7 significant digits in the number, so use w j The corresponding π i Replace w j Set the valid digits in the digits to obtain the second key corresponding to the first key. For example, use w j The corresponding π i Replace w j In practical application, the first set digit can be any digit in the first weight value.
[0060] In practical applications, the weights of general deep neural networks are stored and calculated in the format of float 32, so each weight has many decimal places. Usually, the values in the ones and tenths of the weights have the greatest impact on the calculation accuracy of the neural network model. When the weights of the neural network model are limited to two or three decimal places, the loss of the corresponding neural network model in calculation accuracy and accuracy can be ignored. Therefore, when embedding a watermark in the neural network model, it can be considered to embed the watermark directly into the last few decimal places of the weight.
[0061] Based on this, in one embodiment, embedding the second key as a watermark into the neural network model includes:
[0062] The second key is embedded into at least one second weight of the neural network model.
[0063] When embedding the second key into the second weight, in order not to have a negative impact on the calculation accuracy of the neural network model, in one embodiment, when embedding the second key into at least one second weight of the neural network model, the method includes:
[0064] All digits after the second set digit in the second weight are replaced by the second key.
[0065] Wherein, the second set digit includes a percentile.
[0066] That is, consider replacing all the digits starting from the third decimal point of the second weight with the second key. In this way, the watermark can be transferred to the last decimal place in the weight, that is, the calculation accuracy of the neural network model will not be lost. The watermark can also be directly embedded at the end of the weight, so that there is no need to encrypt the watermark by constructing a hash function and decrypt the watermark when using the neural network model, which improves the calculation efficiency of the neural network model and greatly reduces the occupation of computing resources. In addition, when the neural network model with a watermark is applied to the offline model scenario, when it is suspected that the neural network model has been copied, redistributed or illegally used, by retrieving the relevant weights in the offline neural network model, combined with Figure 1 By using the watermark generation method, the first key is reversely generated and paired with the original first key, the offline model parameters can be reversely decoded and matched with the own secret key to determine whether the neural network model has been copied, redistributed or illegally used.
[0067] In actual application, in order to prevent others from removing the watermark by setting all the data after the weight percentile to 0, in one embodiment, replacing all the digits after the second set digit in the second weight with the second key includes:
[0068] During the training process of the neural network model, all digits after the second set digit in the second weight are replaced with the second key; wherein,
[0069] The second set digit includes a tens digit or a ones digit.
[0070] As mentioned above, since the values of the ones and tenths of the weight have the greatest impact on the calculation accuracy of the neural network model, if the embedded position of the watermark includes the ones or tenths of the weight, that is, the watermark is embedded in the key position that affects the calculation accuracy. In this way, if the watermark is removed from the weight, it will seriously affect the calculation accuracy of the neural network model. Based on this, if the second set digit is ten, the watermark will be embedded in the position that includes the ones and tenths of the weight. If the second set digit is one, the watermark will be embedded in the position that includes the tenths of the weight, so that the watermark cannot be easily removed. In practical applications, when the embedded position of the watermark includes the ones or tenths of the weight, in order to avoid loss of calculation accuracy of the neural network model, the watermark can be added to the neural network model during the training process, and the watermark addition process is combined with the model training process to ensure the performance of the trained neural network model. In practical applications, by adding constraints during the training process, the watermark can be embedded in the key position that affects the calculation accuracy of the network model, so that the watermark cannot be removed.
[0071] The watermarking method provided in the embodiment of the present application determines the N first numerical values included in all digits of the first key, locates N first weights in the neural network model, and each of the N first weights corresponds to a first numerical value of the N numerical values, and obtains the second key by replacing the first numerical value on each digit in the first key with the second numerical value of the corresponding first weight on the set digit, and embeds the second key as a watermark in the neural network model. Here, adding a watermark to the neural network model is achieved based on the weights in the neural network model, which ensures the calculation accuracy of the neural network model and avoids negative impact on the performance of the neural network model.
[0072] The watermark adding method provided in the embodiment of the present application has the following advantages: 1. The key is numerically replaced based on the set digit of the first weight, and the obtained watermark content is embedded into the set position of the second weight. This multi-layer encryption method greatly improves the algorithm complexity of cracking the watermark and will not affect the calculation accuracy of the neural network model; 2. The watermark adding logic can be effectively applied to various offline models; 3. There is no need to construct a codec function, and no additional computing resources are occupied; 4. There is no need to construct a new watermark data; 5. The process of embedding the watermark can be combined with the training process of the neural network model to further avoid the risk of the watermark being removed.
[0073] In order to implement the method of the embodiment of the present application, the embodiment of the present application also provides a watermark adding device, such as Figure 3 As shown, the device comprises:
[0074] A determination unit 301 is used to determine N first values included in all digits of the first key; N is an integer greater than or equal to 1;
[0075] A positioning unit 302, used to locate N weights in the neural network model; each of the N weights corresponds to a first value among the N values;
[0076] The embedding unit 303 is used to embed the second key as a watermark into the neural network model; wherein,
[0077] The second key is obtained by replacing the first value on each digit in the first key with the second value of the corresponding weight on the first set digit.
[0078] In one embodiment, the embedding unit 303 is used to:
[0079] The second key is embedded into at least one second weight of the neural network model.
[0080] In one embodiment, when the embedding unit 303 embeds the second key into at least one second weight of the neural network model, it is used to:
[0081] All digits after the second set digit in the second weight are replaced by the second key.
[0082] In one embodiment, the second set of digits includes a percentile.
[0083] In one embodiment, the embedding unit 303 replaces all digits after the second set digit in the second weight with the second key, including:
[0084] During the training process of the neural network model, all digits after the second set digit in the second weight are replaced with the second key; wherein,
[0085] The second set digit includes a tens digit or a ones digit.
[0086] In one embodiment, the device further comprises:
[0087] The first generating unit is used to randomly generate the first key whose digit length is greater than a first set value.
[0088] In one embodiment, the device further comprises:
[0089] The second generating unit is used to generate the first key based on the digital code corresponding to each character in the set character string.
[0090] In actual application, the determination unit 301, the positioning unit 302, the embedding unit 303, the first generation unit, and the second generation unit may be implemented by a processor in the watermark adding device.
[0091] It should be noted that: the watermark adding device provided in the above embodiment only uses the division of the above program modules as an example to illustrate when adding watermarks. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-described processing. In addition, the watermark adding device provided in the above embodiment and the watermark adding method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0092] Based on the hardware implementation of the above program modules, and in order to implement the watermark adding method of the embodiment of the present application, the embodiment of the present application also provides an electronic device, such as Figure 4 As shown, the electronic device 400 includes:
[0093] The first communication interface 401 is capable of exchanging information with other network nodes;
[0094] The first processor 402 is connected to the first communication interface 401 to implement information exchange with other network nodes, and is used to execute the method provided by one or more of the above technical solutions when running a computer program. The computer program is stored in the first memory 403.
[0095] Specifically, the first processor 402 is used to determine N first values included in all digits of the first key; N is an integer greater than or equal to 1;
[0096] Locating N first weights in the neural network model; each of the N first weights corresponds to a first value among the N values;
[0097] The second key is embedded into the neural network model as a watermark; wherein,
[0098] The second key is obtained by replacing the first value of each digit in the first key with the second value of the corresponding first weight at the first set digit.
[0099] In one embodiment, the first processor 402 embeds the second key as a watermark into the neural network model, including:
[0100] The second key is embedded into at least one second weight of the neural network model.
[0101] In one embodiment, when the first processor 402 embeds the second key into at least one second weight of the neural network model, it is configured to:
[0102] All digits after the second set digit in the second weight are replaced by the second key.
[0103] In one embodiment, the second set of digits includes a percentile.
[0104] In one embodiment, the first processor 402 replaces all digits after the second set digit in the second weight with the second key, including:
[0105] During the training process of the neural network model, all digits after the second set digit in the second weight are replaced with the second key; wherein,
[0106] The second set digit includes a tens digit or a ones digit.
[0107] In one embodiment, the first processor 402 is further configured to:
[0108] The first key is randomly generated, the digital length of which is greater than a first set value.
[0109] In one embodiment, the first processor 402 is further configured to:
[0110] The first key is generated based on the digital code corresponding to each character in the set character string.
[0111] It should be noted that the specific processing process of the first processor 402 can be understood by referring to the above method.
[0112] Of course, in actual application, the various components in the electronic device 400 are coupled together through the bus system 404. It can be understood that the bus system 404 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 404 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 4 Various buses are labeled as bus system 404 .
[0113] The first memory 403 in the embodiment of the present application is used to store various types of data to support the operation of the electronic device 400. Examples of such data include: any computer program used to operate on the electronic device 400.
[0114] The method disclosed in the above embodiment of the present application can be applied to the first processor 402, or implemented by the first processor 402. The first processor 402 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the first processor 402. The above-mentioned first processor 402 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The first processor 402 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the first memory 403, and the first processor 402 reads the information in the first memory 403, and completes the steps of the above method in combination with its hardware.
[0115] In an exemplary embodiment, the electronic device 400 can be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), field programmable gate array (FPGA), general processor, controller, microcontroller (MCU), microprocessor, or other electronic components to execute the aforementioned method.
[0116] It can be understood that the first memory 403 of the embodiment of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAMbus random access memory (DRRAM, Direct Rambus Random Access Memory).The memories described in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.
[0117] In an exemplary embodiment, the present application embodiment further provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, including a first memory 403 storing a computer program, and the computer program can be executed by a first processor 402 of an electronic device 400 to complete the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.
[0118] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0119] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0120] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application.
Claims
1. A watermark adding method, characterized in that: include: Determine N first values included in all digits of the first key, where N is an integer greater than or equal to 1, and the first values represent possible values of each digit of the first key; Locating N first weights in the neural network model; each of the N first weights corresponds to a first value among the N values; The second key is embedded as a watermark in at least one second weight of the neural network model; wherein, The second key is obtained by replacing a second value of the first weight at a first set digit with a first value corresponding to the first weight; The step of embedding the second key as a watermark into at least one second weight of the neural network model comprises: During the training process of the neural network model, all digits after the tens or ones digit in the second weight are replaced with the second key, and constraints are added during the training process so that the second key is embedded in all digits after the tens or ones digit in the second weight of the trained neural network model; or, All digits after the percentile in the second weight are replaced by the second key.
2. The method according to claim 1, characterized in that The method further comprises: The first key is randomly generated, the digital length of which is greater than a first set value.
3. The method according to claim 1, characterized in that The method further comprises: The first key is generated based on the digital code corresponding to each character in the set character string.
4. A watermark adding device, characterized in that: include: A determination unit, configured to determine N first values included in all digits of a first key, wherein N is an integer greater than or equal to 1, and wherein the first values represent possible values of each digit of the first key; A positioning unit, used for positioning N first weights in the neural network model; each first weight in the N first weights corresponds to a first value in the N values; An embedding unit, used to embed the second key as a watermark into at least one second weight of the neural network model; wherein, The second key is obtained by replacing the second value of the first weight at the first set digit with the first value corresponding to the first weight; and embedding the second key as a watermark into at least one second weight of the neural network model comprises: During the training process of the neural network model, all digits after the tens or ones digit in the second weight are replaced with the second key, and constraints are added during the training process so that the second key is embedded in all digits after the tens or ones digit in the second weight of the trained neural network model; or, All digits after the percentile in the second weight are replaced by the second key.
5. An electronic device, characterized in that: include: A first processor and a first communication interface; wherein, The first processor is used to determine N first values included in all digits of the first key; locate N first weights in the neural network model; embed the second key as a watermark in at least one second weight of the neural network model; wherein, The N is an integer greater than or equal to 1; the first value represents the possible values of each digit of the first key; each first weight of the N first weights corresponds to a first value of the N values; the second key is obtained by replacing the second value of the first weight at the first set digit with the first value corresponding to the first weight; the embedding of the second key as a watermark into at least one second weight of the neural network model includes: During the training process of the neural network model, all digits after the tens or ones digit in the second weight are replaced with the second key, and constraints are added during the training process so that the second key is embedded in all digits after the tens or ones digit in the second weight of the trained neural network model; or, All digits after the percentile in the second weight are replaced by the second key.
6. An electronic device, characterized in that: include: a first processor and a first memory for storing a computer program executable on the processor, Wherein, when the first processor is used to run the computer program, the steps of the method described in any one of claims 1 to 3 are executed.
7. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 3 are implemented.
Citation Information
Patent Citations
Information processing apparatus, information processing method and program
JP2019053541A
Protecting deep learning models using watermarking
US20190370440A1