DeepiSign-G: Generic Watermark to Stamp Hidden DNN Parameters for Self-contained Tracking
Alsharif Abuadbba, Nicholas Rhodes, Kristen Moore, Bushra Sabir, Shuo, Wang, Yansong Gao

TL;DR
DeepiSign-G introduces a versatile, fragile watermarking technique embedded in model parameters' Walsh-Hadamard transform coefficients, enabling comprehensive, self-contained verification of CNN and RNN models against various attacks without performance loss.
Contribution
It presents DeepiSign-G, a novel watermarking method applicable to multiple DNN architectures, enhancing security and integrity verification with high detection accuracy and metadata embedding capabilities.
Findings
Effectively detects model modifications across architectures.
Maintains model performance while embedding watermarks.
Achieves nearly perfect attack detection with minimal coefficient hiding.
Abstract
Deep learning solutions in critical domains like autonomous vehicles, facial recognition, and sentiment analysis require caution due to the severe consequences of errors. Research shows these models are vulnerable to adversarial attacks, such as data poisoning and neural trojaning, which can covertly manipulate model behavior, compromising reliability and safety. Current defense strategies like watermarking have limitations: they fail to detect all model modifications and primarily focus on attacks on CNNs in the image domain, neglecting other critical architectures like RNNs. To address these gaps, we introduce DeepiSign-G, a versatile watermarking approach designed for comprehensive verification of leading DNN architectures, including CNNs and RNNs. DeepiSign-G enhances model security by embedding an invisible watermark within the Walsh-Hadamard transform coefficients of the model's…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Steganography and Watermarking Techniques · Video Surveillance and Tracking Methods · Music and Audio Processing
