Show simple item record

dc.contributor.authorCortiñas Lorenzo, Betty 
dc.contributor.authorPerez Gonzalez, Fernando 
dc.date.accessioned2021-03-25T12:18:33Z
dc.date.available2021-03-25T12:18:33Z
dc.date.issued2020-12-06
dc.identifier.citationEntropy, 22(12): 1379 (2020)spa
dc.identifier.issn10994300
dc.identifier.urihttp://hdl.handle.net/11093/1899
dc.description.abstractAs training Deep Neural Networks (DNNs) becomes more expensive, the interest in protecting the ownership of the models with watermarking techniques increases. Uchida et al. proposed a digital watermarking algorithm that embeds the secret message into the model coefficients. However, despite its appeal, in this paper, we show that its efficacy can be compromised by the optimization algorithm being used. In particular, we found through a theoretical analysis that, as opposed to Stochastic Gradient Descent (SGD), the update direction given by Adam optimization strongly depends on the sign of a combination of columns of the projection matrix used for watermarking. Consequently, as observed in the empirical results, this makes the coefficients move in unison giving rise to heavily spiked weight distributions that can be easily detected by adversaries. As a way to solve this problem, we propose a new method called Block-Orthonormal Projections (BOP) that allows one to combine watermarking with Adam optimization with a minor impact on the detectability of the watermark and an increased robustness.spa
dc.language.isoengspa
dc.publisherEntropyspa
dc.rightsCreative Commons Attribution (CC BY) license
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.titleAdam and the ants: on the influence of the optimization algorithm on the detectability of DNN watermarksspa
dc.typearticlespa
dc.rights.accessRightsopenAccessspa
dc.identifier.doi10.3390/e22121379
dc.identifier.editorhttps://www.mdpi.com/1099-4300/22/12/1379spa
dc.publisher.departamentoTeoría do sinal e comunicaciónsspa
dc.publisher.grupoinvestigacionGrupo de Procesado de Sinal en Comunicaciónsspa
dc.subject.unesco3325 Tecnología de las Telecomunicacionesspa
dc.subject.unesco1203.17 Informáticaspa
dc.subject.unesco2209.90 Tratamiento Digital Imágenesspa
dc.date.updated2021-03-25T11:41:01Z


Files in this item

[PDF]

    Show simple item record

    Creative Commons Attribution
(CC BY) license
    Except where otherwise noted, this item's license is described as Creative Commons Attribution (CC BY) license