Skip to content
2000
Volume 2, Issue 6
  • ISSN: 2210-2981
  • E-ISSN: 2210-2914

Abstract

Background: Face recognition belonging to biometric recognition has great application value. Its algorithm based on deep learning has been widely used in recent years. Meanwhile, problems that endanger social privacy and security gradually appear, such as stealing, abusing, and illegal deploying models. Objective: The objective of this study is to use chaos to construct a watermark trigger set for protecting the model's intellectual property rights, thereby enabling the model to resist fine-tuning and overwriting attacks. When the model is leaked, it can be traced through a special watermark. Methods: We used the unpredictability and initial value sensitivity of chaos to make the watermark imperceptible and endow multiple deep learning based face recognition models with special watermarks. Results: The face recognition deep learning model embedded watermarks successfully while having high precision for watermark extraction. Meanwhile, it maintained the original function as well as features of watermarks. Experimental results and theoretical analysis indicate that the proposed scheme can resist fine-tuning, overwriting attacks, and trace leaked models. Conclusion: The proposed scheme improved the model's fidelity, safety, practicality, completeness, effectiveness, and the ability to resist common attacks based on machine learning. With the help of special watermarks, related departments can effectively manage face recognition based on deep learning models.

Loading

Article metrics loading...

/content/journals/ccs/10.2174/2210298102666220411113929
2022-12-01
2025-06-04
Loading full text...

Full text loading...

/content/journals/ccs/10.2174/2210298102666220411113929
Loading
This is a required field
Please enter a valid email address
Approval was a Success
Invalid data
An Error Occurred
Approval was partially successful, following selected items could not be processed due to error
Please enter a valid_number test