2019

DAWN: Dynamic Adversarial Watermarking of Neural Networks

Szyller, Sebastian, Atli, Buse Gul, Marchal, Samuel et al.

Understand

Training machine learning (ML) models is expensive in terms of computational power, amounts of labeled data and human expertise.

  • Thus, ML models constitute intellectual property (IP) and business value for their owners.
  • Embedding digital watermarks during model training allows a model owner to later identify their models in case of theft or misuse.
  • However, model functionality can also be stolen via model extraction, where an adversary trains a surrogate model using results returned from a prediction API of the original model.

Reading the bibliography…