Classifier Training With Watermarked Data for Copy Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing classifier technologies, particularly those based on multi-layer neural networks, are vulnerable to unauthorized copying due to the high resource requirements and complexity, making it difficult to protect the trained weights and detect unauthorized use.

Innovation Solution

Incorporating anomalous markings or watermarks into the training data of classifiers, such as graphical elements or subtle patterns, that are not relevant to the classification task but can be detected through statistical analysis, allowing the detection of unauthorized copying by observing the classifier's response to these markings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multi-layer neural networks are used for classification, then classification accuracy is improved, but vulnerability to unauthorized copying increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidprotection against unauthorized copying
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding watermarks or anomalous markings into the training data before the classifier is trained. These markings are预先 inserted into specific regions of training images (such as background areas or non-critical regions) so that when the classifier learns from this data, it inadvertently learns to respond to these markings. This preliminary modification of training data ensures that any copied classifier will retain these characteristic responses, enabling detection of unauthorized copying while maintaining the classifier's primary functionality.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If complex neural networks are trained, then classification performance is improved, but resource requirements increase

Engineering Contradiction:
Improveclassification performanceVSAvoidresource requirements for training
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by concentrating the watermarking effort only in specific, non-critical regions of the training data rather than modifying the entire dataset uniformly. By targeting specific areas (such as background regions or less important features), the method embeds detection capabilities without requiring extensive modifications to the overall training process or architecture. This localized approach reduces the additional computational resources needed compared to comprehensive modifications.

Inventive Principle:
Principle #3Local quality

3Reliability

If watermarks are embedded in training data, then detection of copying is improved, but classifier functionality may be affected

Engineering Contradiction:
Improvedetection of copyingVSAvoidclassifier functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by embedding watermarks only in specific, non-critical regions of the training data, such as background areas or regions that are less important for the classification task. This ensures that the watermarking process does not interfere with the critical features that the classifier needs to learn for its primary function. By carefully selecting watermark placement locations, the method maintains classifier functionality while enabling copying detection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent converts the potential harm of watermarking (which could interfere with classifier learning) into a benefit by deliberately designing the watermarking process to create detectable anomalies in copied classifiers. The same watermarking that could potentially degrade performance is instead placed in regions where it will not affect primary classification accuracy, but will create characteristic responses that reveal copying. This transforms a potential negative effect into a useful detection mechanism.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS12412228B2Learning systems and methods
Publication Date: 2025.09.09 DIGIMARC CORP
  • US12412228B2 patent drawing
  • US12412228B2 patent drawing
  • US12412228B2 patent drawing

AI summary

A sequence of images depicting an object is captured, e.g., by a camera at a point-of-sale terminal in a retail store. The object is identified, such as by a barcode or watermark that is detected from one or more of the images. Once the object's identity is known, such information is used in training a classifier (e.g., a machine learning system) to recognize the object from others of the captured images, including images that may be degraded by blur, inferior lighting, etc. In another arrangement, such degraded images are processed to identify feature points useful in fingerprint-based identification of the object. Feature points extracted from such degraded imagery aid in fingerprint-based recognition of objects under real life circumstances, as contrasted with feature points extracted from pristine imagery (e.g., digital files containing label artwork for such objects). A great variety of other features and arrangements—some involving designing classifiers so as to combat classifier copying—are also detailed.