Related Experiment Video
Updated: Mar 12, 2026

09:20
Picoinjection of Microfluidic Drops Without Metal Electrodes
Published on: April 18, 2014
11.7K
Safe and Robust Watermark Injection with a Single OoD Image
Shuyang Yu1, Junyuan Hong1,2, Haobo Zhang1
1Department of Computer Science and Engineering, Michigan State University.
Summary
This study introduces a novel deep neural network watermarking method using a single out-of-distribution image. This technique offers robust intellectual property protection against common removal attacks without needing training data.
Area of Science:
- Artificial Intelligence
- Computer Science
- Machine Learning Security
Background:
- Deep neural networks (DNNs) demand significant data and computational power.
- Protecting intellectual property (IP) for DNNs is a critical challenge.
- Existing watermarking methods often rely on training data poisoning, raising privacy concerns and lacking robustness against model modifications.
Purpose of the Study:
- To propose a safe and robust backdoor-based watermarking technique for DNNs.
- To develop a method for IP verification independent of training data.
- To enhance watermark resilience against common removal attacks.
Main Methods:
- A novel watermarking technique leveraging a single out-of-distribution (OoD) image as a secret key.
- Injection of backdoor triggers using the OoD image's diverse knowledge.
- Inducing robustness through random perturbation of model parameters during watermark injection.
Main Results:
- The proposed method is time- and sample-efficient, requiring no access to training data.
- Demonstrated robustness against common watermark removal attacks like fine-tuning, pruning, and model extraction.
- Effective IP verification through the unique secret key derived from the OoD image.
Conclusions:
- The developed watermarking approach provides a secure and resilient solution for DNN intellectual property protection.
- The method overcomes the limitations of traditional watermarking techniques by eliminating the need for training data and enhancing robustness.
- This technique offers a practical and efficient way to safeguard commercial ownership of deep learning models.

