Abstract
Background: Face recognition belonging to biometric recognition has great application value. Its algorithm based on deep learning has been widely used in recent years. Meanwhile, problems that endanger social privacy and security gradually appear, such as stealing, abusing, and illegal deploying models.
Objective: The objective of this study is to use chaos to construct a watermark trigger set for protecting the model's intellectual property rights, thereby enabling the model to resist fine-tuning and overwriting attacks. When the model is leaked, it can be traced through a special watermark.
Methods: We used the unpredictability and initial value sensitivity of chaos to make the watermark imperceptible and endow multiple deep learning based face recognition models with special watermarks.
Results: The face recognition deep learning model embedded watermarks successfully while having high precision for watermark extraction. Meanwhile, it maintained the original function as well as features of watermarks. Experimental results and theoretical analysis indicate that the proposed scheme can resist fine-tuning, overwriting attacks, and trace leaked models.
Conclusion: The proposed scheme improved the model's fidelity, safety, practicality, completeness, effectiveness, and the ability to resist common attacks based on machine learning. With the help of special watermarks, related departments can effectively manage face recognition based on deep learning models.
Keywords: Deep learning, face recognition, intelligent model protection, chaos theory, Lorenz chaotic system, watermark.
Graphical Abstract
[http://dx.doi.org/10.1561/0400000042]
[http://dx.doi.org/10.1109/ACCESS.2017.2737544]
[http://dx.doi.org/10.1145/3078971.3078974]
[http://dx.doi.org/10.1109/ICASSP.2019.8682202]
[http://dx.doi.org/10.1145/3196494.3196550]
[http://dx.doi.org/10.1145/3321705.3329808]
[http://dx.doi.org/10.1109/TPAMI.2021.3064850]
[http://dx.doi.org/10.7498/aps.70.20210561]
[http://dx.doi.org/10.7498/aps.69.20201019]
[http://dx.doi.org/10.7498/aps.68.20190553]
[http://dx.doi.org/10.1016/j.sigpro.2019.107373]
[http://dx.doi.org/10.1016/j.physa.2008.02.020]
[http://dx.doi.org/10.1007/s11071-020-05601-x]
[http://dx.doi.org/10.1007/s11071-018-4100-x]