Watermarking for Out-of-distribution Detection
Qizhou Wang, Feng Liu, Yonggang Zhang, Jing Zhang, Chen Gong, Tongliang Liu, Bo Han
Abstract
Out-of-distribution (OOD) detection aims to identify OOD data based on representations extracted from well-trained deep models. However, existing methods largely ignore the reprogramming property of deep models and thus may not fully unleash their intrinsic strength: without modifying parameters of a well-trained deep model, we can reprogram this model for a new purpose via data-level manipulation (e.g., adding a specific feature perturbation to the data). This property motivates us to reprogram a classification model to excel at OOD detection (a new task), and thus we propose a general methodology named watermarking in this paper. Specifically, we learn a unified pattern that is superimposed onto features of original data, and the model's detection capability is largely boosted after watermarking. Extensive experiments verify the effectiveness of watermarking, demonstrating the significance of the reprogramming property of deep models in OOD detection. The code is publicly available at: github.com/qizhouwang/watermarking.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e832fdd7-f16c-4333-9d82-bd0c85fc508dCited by top-tier papers25
- Out-of-distribution Detection Learning with Unreliable Out-of-distribution SourcesHaotian Zheng, Qizhou Wang, Zhen Fang, Xiaobo Xia et al.NeurIPS 2023 · 53 citations
- FlatMatch: Bridging Labeled Data and Unlabeled Data with Cross-Sharpness for Semi-Supervised LearningZhuo Huang, Li Shen, Jun Yu, Bo Han et al.NeurIPS 2023 · 50 citations
- Out-of-Distribution Detection with Negative PromptsJun Nie, Yonggang Zhang, Zhen Fang, Tongliang Liu et al.ICLR 2024 · 48 citations
- How Does Unlabeled Data Provably Help Out-of-Distribution Detection?Xuefeng Du, Zhen Fang, Ilias Diakonikolas, Yixuan LiICLR 2024 · 39 citations
- Envisioning Outlier Exposure by Large Language Models for Out-of-Distribution DetectionChentao Cao, Zhun Zhong, Zhanke Zhou, Yang Liu et al.ICML 2024 · 34 citations
Builds on25
- Energy-based Out-of-distribution DetectionWeitang Liu, Xiaoyun Wang, John D. Owens, Yixuan LiNeurIPS 2020 · 2,213 citations
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 1,861 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- CSI: Novelty Detection via Contrastive Learning on Distributionally Shifted InstancesJihoon Tack, Sangwoo Mo, Jongheon Jeong, Jinwoo ShinNeurIPS 2020 · 755 citations
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 743 citations
Related papers
- Towards Optimal Feature-Shaping Methods for Out-of-Distribution DetectionQinyu Zhao, Ming Xu, Kartik Gupta, Akshay Asthana et al.ICLR 2024 · 14 citations
- Safe and Robust Watermark Injection with a Single OoD ImageShuyang Yu, Junyuan Hong, Haobo Zhang, Haotao Wang et al.ICLR 2024 · 4 citations
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Unleashing Mask: Explore the Intrinsic Out-of-Distribution Detection CapabilityJianing Zhu, Hengzhuang Li, Jiangchao Yao, Tongliang Liu et al.ICML 2023 · 20 citations
- Rethinking Out-of-distribution (OOD) Detection: Masked Image Modeling is All You NeedJingyao Li, Pengguang Chen, Zexin He, Shaozuo Yu et al.CVPR 2023
