Related Experiment Video
Updated: Jul 16, 2026

04:48
Application of Deep Learning-Based Medical Image Segmentation via Orbital Computed Tomography
Published on: November 30, 2022
Stealthy watermarking for medical AI models via spatial patch trigger and two-stage training
1Department of Artificial Intelligence and Data Science, Korea Military Academy, Seoul, 01805, South Korea.
Scientific Reports
|July 14, 2026
Summary
Protecting ownership of medical AI models is crucial. This study introduces a stealthy watermarking framework that embeds ownership information without compromising diagnostic accuracy, using a novel spatial patch trigger and two-stage training for deep learning models.
Area of Science:
- Artificial Intelligence
- Medical Imaging
- Computer Vision
Background:
- Deep learning models in medical image analysis are valuable intellectual property, requiring robust protection methods.
- Existing watermarking techniques often degrade diagnostic accuracy or introduce unacceptable artifacts in clinical settings.
Purpose of the Study:
- To propose a stealthy watermarking framework for medical AI models that protects intellectual property.
- To ensure watermarking does not compromise diagnostic accuracy or introduce visible artifacts in clinical applications.
Main Methods:
- A spatial patch trigger mechanism mimicking natural dermoscopic image phenomena was employed.
- A two-stage training strategy decoupled feature learning from watermark embedding, optimizing classification and watermarking.
- The method was evaluated on the ISIC 2018 Skin Lesion Analysis dataset using a ResNet-50 backbone.
Main Results:
- The proposed method achieved a 94.08% watermark success rate while maintaining 76.16% classification fidelity.
- The accuracy gap to the clean baseline was reduced, and run-to-run variance was lowered.
- Watermark triggers were perceptually indistinguishable (SSIM: 0.984, LPIPS: 0.060) and robust to attacks.
Conclusions:
- The developed framework offers a practical solution for protecting intellectual property in medical AI.
- The method provides a quantified and honestly reported trade-off between ownership protection and classification accuracy.