Towards the Resistance of Neural Network Fingerprinting to Fine-tuning
Ling Tang, Yuefeng Chen, Hui Xue', Quanshi Zhang
Abstract
This paper proves a new fingerprinting method to embed the ownership information into a deep neural network (DNN) with theoretically guaranteed robustness to fine-tuning. Specifically, we prove that when the input feature of a convolutional layer only contains low-frequency components, specific frequency components of the convolutional filter will not be changed by gradient descent during the fine-tuning process, where we propose a revised Fourier transform to extract frequency components from the convolutional filter. Additionally, we also prove that these frequency components are equivariant to weight scaling and weight permutations. In this way, we design a fingerprint module to embed the fingerprint information into specific frequency components of convolutional filters. Preliminary experiments demonstrate the effectiveness of our method. The source code has been released at https://github.com/tling2000/watermark.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7ac9ccbf-b89b-439c-8764-7a04fe5f5157Cited by top-tier papers2
- Fingerprinting Deep Neural Networks for Ownership Protection: An Analytical ApproachGuang Yang, Ziye Geng, Yihang Chen, Changqing LuoICLR 2026 · 3 citations
- LiteGuard: Efficient Task-Agnostic Model Fingerprinting with Enhanced GeneralizationGuang Yang, Ziye Geng, Yihang Chen, Changqing LuoICLR 2026 · 2 citations
Builds on14
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz et al.ICML 2023 · 854 citations
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Entangled Watermarks as a Defense against Model ExtractionHengrui Jia, Christopher A. Choquette-Choo, Varun Chandrasekaran, Nicolas PapernotUSENIX Security 2021 · 287 citations
- DAWN: Dynamic Adversarial Watermarking of Neural NetworksSebastian Szyller, Buse Gul Atli, Samuel Marchal, N. AsokanACM MM 2021 · 133 citations
- Passport-aware Normalization for Deep Model ProtectionJie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang et al.NeurIPS 2020 · 108 citations
Related papers
- Identification for Deep Neural Network: Simply Adjusting Few Weights!Yingjie Lao, Peng Yang, Weijie Zhao, Ping LiICDE 2022 · 19 citations
- Watermarking Deep Neural Networks with Greedy ResidualsHanwen Liu, Zhenyu Weng, Yuesheng ZhuICML 2021 · 69 citations
- Fingerprinting Deep Image Restoration ModelsYuhui Quan, Huan Teng, Ruotao Xu, Jun Huang et al.ICCV 2023 · 8 citations
- Hashed Watermark as a Filter: A Unified Defense Against Forging and Overwriting Attacks in Neural Network WatermarkingYuan Yao, Jin Song, Jian JinAAAI 2026
- Towards Robust Model Watermark via Reducing Parametric VulnerabilityGuanhao Gan, Yiming Li, Dongxian Wu, Shu-Tao XiaICCV 2023 · 18 citations
