Dual-Locking Learned AI Models: A PIN-Based Sparse QIM Watermarking and Adaptive Index Permutation Approach

📅 2026-09-19
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出一种结合基于PIN的稀疏QIM水印和自适应索引置换的双锁定方法,以保护训练好的神经网络免受未经授权的使用。
📝 Abstract
We present a dual-locking method for securing trained neural networks that combines key-driven index permutation with PIN-based watermarking based on Sparse Quantization Index Modulation (QIM). Cryptographic randomness is introduced by independently applying a uniform random permutation to each row of adaptively selected index vectors. A robust blind binary watermark is then embedded into the bias coefficients by modulating their quantized values, binding the network to a user-defined Personal Identification Number (PIN). Without the correct key, the network retains its architecture but becomes functionally impaired due to disrupted internal representations. Inverse permutation fully restores the original model accuracy, while the embedded watermark remains imperceptible and enables blind verification of key association and model authorship. To improve both locking effectiveness and recoverability, an adaptive key selection strategy redistributes high-magnitude weights to low-sensitivity positions and vice versa, increasing degradation in the locked state while preserving full recovery. Experiments on MNIST, CIFAR-10/100, and ImageNet-1K using fully connected networks, ResNet CNNs, and transformer architectures show that locking reduces accuracy below 10\%, and even below 0.5\% for CNNs, while the correct key fully restores performance. The watermark introduces no measurable accuracy degradation and reliably authenticates ownership. Analysis of embedding distributions across CNNs and transformers further indicates potential diagnostic value for identifying undertrained or suboptimally designed models. The proposed approach therefore provides simultaneous model protection, recovery, and ownership verification.
Problem

Research questions and friction points this paper is trying to address.

neural network security
model protection
watermarking
ownership verification
functional impairment
Innovation

Methods, ideas, or system contributions that make the work stand out.

Dual-Locking
Sparse QIM Watermarking
Adaptive Index Permutation
Neural Network Security
Blind Verification
I
Iva Vasic
Faculty of Science and Medicine, University of Fribourg, 1700 Fribourg, Switzerland
J
Jesús Muñoz-Cádiz
Faculty of Science and Medicine, University of Fribourg, 1700 Fribourg, Switzerland
B
Bata Vasic
Faculty of Electronic Engineering, University of Niš, 18000 Niš, Serbia; on leave from Information Technology Department, University MB, 11040 Belgrade, Serbia