Trapdoor Normalization with Irreversible Ownership Verification
Hanwen Liu, Zhenyu Weng, Yuesheng Zhu, Yadong Mu
Abstract
This paper introduces a deep model watermark with an irreversible ownership verification scheme: Trapdoor Normalization (TdN), inspired by the trapdoor function in traditional cryptography. To protect intellectual property within deep models, the proposed method is able to embed ownership information into normalization layers during training. We argue and empirically validate that relevant methods are vulnerable to ambiguity attacks, where the forged watermarks can cast ambiguity over the ownership verification. The primary trait that distinguishes this work from previous ones, is its design of a bidirectional connection between watermarks and deep models. Thereby, TdN enables an irreversible ownership verification scheme that is difficult for the adversary to compromise. In this way, the proposed TdN can effectively defeat ambiguity attacks. Extensive experiments demonstrate that the proposed method is not only superior to previous state-of-the-art methods in robustness, but also has better efficiency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 49f56b9c-9de4-4d23-a604-20cfabcf059cCited by top-tier papers5
- Unlearning Concepts in Diffusion Model via Concept Domain Correction and Concept Preserving GradientYongliang Wu, Shiji Zhou, Mingzhuo Yang, Lianzhe Wang et al.AAAI 2025 · 69 citations
- Cert-LAS: Toward Certified Model Ownership Verification for Text-to-Image Diffusion Models via Layer-Adaptive SmoothingLeyi Qi, Yiming Li, Siyuan Liang, Zhengzhong Tu et al.ICML 2026 · 1 citation
- Steganographic Passport: An Owner and User Verifiable Credential for Deep Model IP Protection Without RetrainingQi Cui, Ruohan Meng, Chaohui Xu, Chip-Hong ChangCVPR 2024
- Hashed Watermark as a Filter: A Unified Defense Against Forging and Overwriting Attacks in Neural Network WatermarkingYuan Yao, Jin Song, Jian JinAAAI 2026
- Removing Concepts from Text-to-Image Models with Only Negative SamplesHanwen Liu, Yadong MuNeurIPS 2025
Builds on13
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
Related papers
- Effective Ambiguity Attack Against Passport-based DNN Intellectual Property Protection Schemes through Fully Connected Layer SubstitutionYiming Chen, Jinyu Tian, Xiangyu Chen, Jiantao ZhouCVPR 2023
- Watermarking Deep Neural Networks with Greedy ResidualsHanwen Liu, Zhenyu Weng, Yuesheng ZhuICML 2021 · 69 citations
- Passport-aware Normalization for Deep Model ProtectionJie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang et al.NeurIPS 2020 · 108 citations
- Towards Robust Model Watermark via Reducing Parametric VulnerabilityGuanhao Gan, Yiming Li, Dongxian Wu, Shu-Tao XiaICCV 2023 · 18 citations
- Authority Backdoor: A Certifiable Backdoor Mechanism for Authoring DNNsHan Yang, Shaofeng Li, Tian Dong, Xiangyu Xu et al.AAAI 2026
