A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2021; you can also visit the original URL.
The file type is application/pdf
.
SoK: How Robust is Image Classification Deep Neural Network Watermarking? (Extended Version)
[article]
2021
arXiv
pre-print
Deep Neural Network (DNN) watermarking is a method for provenance verification of DNN models. Watermarking should be robust against watermark removal attacks that derive a surrogate model that evades provenance verification. Many watermarking schemes that claim robustness have been proposed, but their robustness is only validated in isolation against a relatively small set of attacks. There is no systematic, empirical evaluation of these claims against a common, comprehensive set of removal
arXiv:2108.04974v1
fatcat:xouwi2nb65gota6xqtqqbmn5ue