Protecting Intellectual Property of EEG-based Model with Watermarking

被引:2
|
作者
Xu, Tianhua [1 ]
Zhong, Sheng-Hua [1 ]
Xiao, Zhijiao [1 ]
机构
[1] Shenzhen Univ, Coll Comp Sci & Software Engn, Shenzhen, Peoples R China
基金
中国国家自然科学基金;
关键词
EEG-based model protection; model watermarking; Intellectual Property (IP);
D O I
10.1109/ICME55011.2023.00015
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Sharing learned models is crucial in research and the industry's rapid development and progress. Meanwhile, as the Intellectual Property (IP) of the model proposer, the learned high-performance models must be protected to avoid being illegally copied or redistributed by malicious users. Unfortunately, even though the field of Electroencephalography (EEG) has made significant progress and the models are becoming increasingly complex, more work still needs to be done on protecting EEG-based models. The damage caused by model stealing and attack on the brain-computer interface (BCI) is more severe than in other fields. In this paper, we propose a method that protects the IP of EEG-based models with watermarking for the first time. Watermarks are embedded into three representative EEG-based models by designing a trigger set. On the premise of not sacrificing the primary task's performance significantly, the models' legality can be verified remotely through the trigger set. Furthermore, we demonstrate that the proposed model protection method is robust to various anti-watermarking attacks, such as fine-tuning, transfer learning, pruning, and watermark overwriting.
引用
收藏
页码:37 / 42
页数:6
相关论文
共 50 条
  • [1] Protecting Intellectual Property of Deep Neural Networks with Watermarking
    Zhang, Jialong
    Gu, Zhongshu
    Jang, Jiyong
    Wu, Hui
    Stoecklin, Marc Ph
    Huang, Heqing
    Molloy, Ian
    PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, : 159 - 171
  • [2] Protecting the Intellectual Property of Speaker Recognition Model by Black-Box Watermarking in the Frequency Domain
    Wang, Yumin
    Wu, Hanzhou
    SYMMETRY-BASEL, 2022, 14 (03):
  • [3] Protecting the Intellectual Property of Deep Neural Networks with Watermarking: The Frequency Domain Approach
    Li, Meng
    Zhong, Qi
    Zhang, Leo Yu
    Du, Yajuan
    Zhang, Jun
    Xiang, Yong
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 402 - 409
  • [4] Protecting Intellectual Property
    Welander, Peter
    CONTROL ENGINEERING, 2010, 57 (04) : 46 - 48
  • [5] Protecting intellectual property
    不详
    ANTI-CORROSION METHODS AND MATERIALS, 2000, 47 (05) : 298 - 298
  • [6] Protecting intellectual property
    Lemetais, C
    CHEMICAL ENGINEER-LONDON, 2000, (703): : 18 - 18
  • [7] Protecting intellectual property
    Lanzerotti, LJ
    SPACE WEATHER-THE INTERNATIONAL JOURNAL OF RESEARCH AND APPLICATIONS, 2004, 2 (01):
  • [8] Protecting intellectual property
    Brickley, P
    SCIENTIST, 2001, 15 (21): : 30 - 30
  • [9] PROTECTING INTELLECTUAL PROPERTY
    BAHN, GS
    MECHANICAL ENGINEERING, 1994, 116 (10) : 8 - 8
  • [10] PROTECTING INTELLECTUAL PROPERTY
    不详
    BULLETIN OF THE AMERICAN SOCIETY FOR INFORMATION SCIENCE, 1993, 19 (02): : 11 - 11