Robust and Secure Deep Neural Network Watermarking Technique Shows Promise

Researchers from IMT Atlantique have presented a new deep neural network watermarking technique, RoSe-Mix, designed for black-box settings. According to the study, RoSe-Mix addresses limitations in existing DNN watermarking approaches by integrating key features from two established methods: RoSe, which uses cryptographic hashing to ensure security, and Mixer, which employs image Mixup to enhance robustness. The experimental results demonstrate that RoSe-Mix achieves security across various architectures and datasets with a robustness to removal attacks exceeding 99%.

Key Takeaways:

  • The new technique, RoSe-Mix, is designed to provide robust and secure deep neural network watermarking in black-box settings.
  • RoSe-Mix combines key features from two established methods: RoSe and Mixer, to enhance security and robustness.
  • The experimental results show that RoSe-Mix achieves security across various architectures and datasets with a robustness to removal attacks exceeding 99%.
  • The study concluded that RoSe-Mix addresses limitations in existing DNN watermarking approaches.
  • The researchers include Tamara El Hajjar, Mohammed Lansari, Reda Bellafqira, Gouenou Coatrieux, Katarzyna Kapusta, and Kassem Kallas.
  • The research was funded by the European Union, Cybaile Industrial Chair, and Agence Nationale De La Recherche.

Statistics:

  • Robustness to removal attacks: 99%
  • Security across various architectures and datasets: Achieved
  • Number of researchers involved: 7
  • Funding sources: European Union, Cybaile Industrial Chair, Agence Nationale De La Recherche

Sources:

  • RoSe-Mix: Robust and Secure Deep Neural Network Watermarking in Black-Box Settings via Image Mixup. Machine Learning and Knowledge Extraction, 2023,7(2):32.
  • https://doi.org/10.3390/make7020032
  • Information Technology Newsweekly, July 8, 2025, p 1048.
  • NewsRx. Researchers from IMT Atlantique Report on Findings in Knowledge Extraction (RoSe-Mix: Robust and Secure Deep Neural Network Watermarking in Black-Box Settings via Image Mixup).