Steganographic Passport: An Owner and User Verifiable Credential for Deep Model IP Protection Without Retraining
Qi Cui, Ruohan Meng, Chaohui Xu, Chip-Hong Chang
Abstract
Ensuring the legal usage of deep models is crucial to promoting trustable, accountable, and responsible artificial intelligence innovation. Current passport-based methods that obfuscate model functionality for license-to-use and ownership verifications suffer from capacity and quality constraints, as they require retraining the owner model for new users. They are also vulnerable to advanced Expanded Residual Block ambiguity attacks. We propose Steganographic Passport, which uses an invertible steganographic network to decouple license-to-use from ownership verification by hiding the user's identity images into the owner-side passport and recovering them from their respective userside passports. An irreversible and collision-resistant hash function is used to avoid exposing the owner-side passport from the derived user-side passports and increase the uniqueness of the model signature. To safeguard both the passport and model's weights against advanced ambiguity attacks, an activation-level obfuscation is proposed for the verification branch of the owner's model. By jointly training the verification and deployment branches, their weights become tightly coupled. The proposed method supports agile licensing of deep models by providing a strong ownership proof and license accountability without requiring a separate model retraining for the admission of every new user. Experiment results show that our Steganographic Passport outperforms other passport-based deep model protection methods in robustness against various known attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 81f54fb2-c747-4e04-aae6-c91753b2e0f4Cited by top-tier papers1
Ask how each one uses itBuilds on10
- HiNet: Deep Image Hiding by Invertible NetworkJunpeng Jing, Xin Deng, Mai Xu, Jianyi Wang et al.ICCV 2021 · 301 citations
- Entangled Watermarks as a Defense against Model ExtractionHengrui Jia, Christopher A. Choquette-Choo, Varun Chandrasekaran, Nicolas PapernotUSENIX Security 2021 · 287 citations
- Passport-aware Normalization for Deep Model ProtectionJie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang et al.NeurIPS 2020 · 108 citations
- Fingerprinting Deep Neural Networks Globally via Universal Adversarial PerturbationsZirui Peng, Shaofeng Li, Guoxing Chen, Cheng Zhang et al.CVPR 2022 · 66 citations
- Reversible Watermarking in Deep Convolutional Neural Networks for Integrity AuthenticationXiquan Guan, Huamin Feng, Weiming Zhang, Hang Zhou et al.ACM MM 2020 · 46 citations
Related papers
- Effective Ambiguity Attack Against Passport-based DNN Intellectual Property Protection Schemes through Fully Connected Layer SubstitutionYiming Chen, Jinyu Tian, Xiangyu Chen, Jiantao ZhouCVPR 2023
- Trapdoor Normalization with Irreversible Ownership VerificationHanwen Liu, Zhenyu Weng, Yuesheng Zhu, Yadong MuICML 2023 · 9 citations
- Watermarking Deep Neural Networks with Greedy ResidualsHanwen Liu, Zhenyu Weng, Yuesheng ZhuICML 2021 · 69 citations
- Robust Secure Swap: Responsible Face Swap With Persons of Interest Redaction and Provenance TraceabilityYunshu Dai, Jianwei Fei, Fangjun Huang, Chip Hong ChangICML 2025
- DeepTracer: Tracing Stolen Model via Deep Coupled WatermarksYunfei Yang, Xiaojun Chen, Yuexin Xuan, Zhendong Zhao et al.AAAI 2026
