Nova Patents
EP4127984A1

Neural network watermarking

Abstract

This record has no abstract on file.

EP4127984A1, drawing sheet 1
Sheet 1 of 5

Term

13.5 yearsto projected expiry

Projected expiry 1 April 2040, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

24 claims: 23 independent, 1 dependent

  1. 1
    Claims of equivalent WO 2021197600 A1 CLAIMS1. A method for training a neural network and embedding a watermark in the neural network, wherein the watermark is for proving ownership of the neural network, and wherein the neural network comprises a plurality of trainable parameters associated with a number of network nodes, the method comprising:splitting the plurality of trainable parameters into a first set of trainable parameters and a second set of trainable parameters;inputting a first set of training samples to the neural network;training the neural network by iterating the first set of training samples through the neural self learning network to update the first set of trainable parameters and hindering the second set of trainable parameters to be updated during iteration of the first set of training samples;inputting a second set of training samples, to the neural network;and embedding the watermark by iterating the second set of training samples through the neural network to update the second set of trainable parameters and hindering the first set of trainable parameters to be updated during iteration of the second set of training samples.
  2. 2
    The method according to the previous claim, wherein the first set of trainable parameters and the second set of trainable parameters form parallel layers in the neural network and wherein the method further comprises iterating the first set of training samples and the second set of training samples through the respective set of trainable parameters in sequence.
  3. 3
    The method according to any of the previous claims, further comprising choosing the second set of training samples to comprise a first number of training samples;and choosing the second set of trainable parameters to comprise a second number of trainable parameters, wherein the first number is smaller than the second number.
  4. 4
    The method according to any of the previous claims, wherein the first set of training samples comprises general training samples for training the neural network, and wherein the second set of training samples comprises training samples for watermarking.
  5. 6
    The method according to any of the previous claims 1-5, wherein the second set of training samples comprises training samples from the first set of training samples.
  6. 7
    The method according to claim any of the previous claims 1-6, wherein the second set of training samples comprises training samples from the first set of training samples that have been misclassified by the neural network during iteration of the first set of training samples.
  7. 8
    The method according to any of the previous claims 1-4, wherein the second set of training samples comprises training samples unrelated to the first set of training samples.
  8. 9
    The method according to any of the previous claims, wherein the second set of training samples comprises training samples formed by noise.
  9. 10
    The method according to any of the previous claims, further comprising iterating the second set of training samples through the second set of trainable parameters until a classification confidence associated with the second set of training samples is above a confidence threshold.
  10. 11
    A method for extracting a watermark embedded according to any of the claims 1-10 in a neural network, wherein the watermark is for proving ownership of the neural network and wherein the neural network comprises a plurality of trainable parameters associated with a number of network nodes, the method comprising inputting at least one key sample to the neural network, wherein the at least one key sample is associated with the embedded watermark; and evaluating an output from the neural network by performing at least one of:determining that a confidence value associated with the output of the at least one key sample inputted to the neural network is above a confidence threshold;and determining that a predetermined subset of network nodes of the number of network nodes are activated when the at least one key sample is inputted to the neural network.
  11. 12
    A computer program product comprising a non-transitory computer readable medium, wherein the non-transitory computer readable medium has stored thereon a computer program comprising program instructions, wherein the computer program is configured to be loadable into a data-processing unit, comprising a processor and a memory associated with or integral to the data-processing unit, wherein when loaded into the data-processing unit, the computer program is configured to be stored in the memory, wherein the computer program, when loaded into and run by the processor is configured to cause the execution of method steps according to any of the methods described in conjunction with the claims 1-11.
  12. 13
    An apparatus for training a neural network and embedding a watermark in the neural network, wherein the watermark is for proving ownership of the neural network, and wherein the neural network comprises a plurality of trainable parameters associated with a number of network nodes, the apparatus comprising a controller configured to cause:splitting of the plurality of trainable parameters into a first set of trainable parameters and a second set of trainable parameters;inputting of a first set of training samples to the neural network;training of the neural network by iteration of the first set of training samples through the neural self learning network to update the first set of trainable parameters and hindering the second set of trainable parameters to be updated during iteration of the first set of training samples;inputting of a second set of training samples, to the neural network;and embedding of the watermark by iteration of the second set of training samples through the neural network to update the second set of trainable parameters and hindering the first set of trainable parameters to be updated during iteration of the second set of training samples.
  13. 14
    The apparatus according to the previous claim 13, wherein the first set of trainable parameters and the second set of trainable parameters form parallel layers in the neural network and wherein the controller is further configured to cause iteration of the first set of training samples and the second set of training samples through the respective set of trainable parameters in sequence.
  14. 15
    The apparatus according to any of the previous claims 13-14, wherein the controller is further configured to cause choosing of the second set of training samples to comprise a first number of training samples;and choosing of the second set of trainable parameters to comprise a second number of trainable parameters, wherein the first number is smaller than the second number.
  15. 16
    The apparatus according to any of the previous claims 13-15, wherein the first set of training samples comprises general training samples for training the neural network, and wherein the second set of training samples comprises training samples for watermarking.
  16. 17
    The apparatus according to any of the previous claims 13-16, wherein the controller is further configured to cause training of the neural network to associate the training samples for watermarking of the second set of training samples with an unexpected class.
  17. 18
    The apparatus according to any of the previous claims 13-17, wherein the second set of training samples comprises training samples from the first set of training samples.
  18. 19
    The apparatus according to claim any of the previous claims 13-18, wherein the second set of training samples comprises training samples from the first set of training samples that have been misclassified by the neural network during iteration of the first set of training samples.
  19. 20
    The apparatus according to any of the previous claims 13-16, wherein the second set of training samples comprises training samples unrelated to the first set of training samples.
  20. 21
    The apparatus according to any of the previous claims 13-20, wherein the second set of training samples comprises training samples formed by noise.
  21. 22
    The apparatus according to any of the previous claims 13-21, wherein the controller is further configured to cause iteration of the second set of training samples through the second set of trainable parameters until a classification confidence associated with the second set of training samples is above a confidence threshold.
  22. 23
    An apparatus for extracting a watermark embedded according to any of the claims 1-10 in a neural network, wherein the watermark is for proving ownership of the neural network and wherein the neural network comprises a plurality of trainable parameters associated with a number of network nodes, the apparatus comprising a controller configured to cause inputting of at least one key sample to the neural network, wherein the at least one key sample is associated with the embedded watermark; and evaluation of an output from the neural network by performing at least one of:determination of that a confidence value associated with the output of the at least one key sample inputted to the neural network is above a confidence threshold;and determination of that a predetermined subset of network nodes of the number of network nodes are activated when the at least one key sample is inputted to the neural network.
  23. 24
    A computer comprising a neural network and the apparatus according to any of the claims12-23 for training the neural network and embedding a watermark in the neural network and/or extracting an embedded watermark from the neural network.
Independent claims23