Invention Grant
- Patent Title: Method for watermarking a machine learning model
-
Application No.: US16779737Application Date: 2020-02-03
-
Publication No.: US11809531B2Publication Date: 2023-11-07
- Inventor: Wilhelmus Petrus Adrianus Johannus Michiels
- Applicant: NXP B.V.
- Applicant Address: NL Eindhoven
- Assignee: NXP B.V.
- Current Assignee: NXP B.V.
- Current Assignee Address: NL Eindhoven
- Agent Daniel D. Hill
- Main IPC: G06F21/16
- IPC: G06F21/16 ; G06N3/02 ; G06N5/04 ; G06N20/00

Abstract:
A method is provided for watermarking a machine learning model. In the method, a first subset of a labeled set of ML training samples is selected. The first subset is of a predetermined class of images. A first pixel pattern is selected and inserted into each sample of the first subset. One or more of a location, position, orientation, and transformation of the first pixel pattern is varied for each of the samples. Each sample of the first subset is relabeled to have a different label than the original label. The ML model is trained with the labeled set of ML training samples and the first subset of relabeled ML training samples. To detect the watermark, a second subset of training samples is selected, and the first pixel pattern is inserted into each sample. The second subset is used during inference operation to detect the presence of the watermark.
Public/Granted literature
- US20210240803A1 METHOD FOR WATERMARKING A MACHINE LEARNING MODEL Public/Granted day:2021-08-05
Information query