{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T11:38:25Z","timestamp":1761737905373,"version":"build-2065373602"},"reference-count":36,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2025,10,26]],"date-time":"2025-10-26T00:00:00Z","timestamp":1761436800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>The integration of artificial intelligence (AI) and edge computing gives rise to edge intelligence (EI), which offers effective solutions to the limitations of traditional cloud-based AI; however, deploying models across distributed edge platforms raises concerns regarding authenticity, thereby necessitating robust mechanisms for ownership verification. Currently, backdoor-based model watermarking techniques represent a state-of-the-art approach for ownership verification; however, their reliance on model poisoning introduces potential security risks and unintended behaviors. To solve this challenge, we propose BIMW, a blockchain-enabled innocuous model watermarking framework that ensures secure and trustworthy AI model deployment and sharing in distributed edge computing environments. Unlike widely applied backdoor-based watermarking methods, BIMW adopts a novel innocuous model watermarking method called interpretable watermarking (IW), which embeds ownership information without compromising model integrity or functionality. In addition, BIMW integrates a blockchain security fabric to ensure the integrity and auditability of watermarked data during storage and sharing. Extensive experiments were conducted on a Jetson Orin Nano board, which simulates edge computing environments. The numerical results show that our framework outperforms baselines in terms of predicate accuracy, p-value, watermark success rate (WSR), and harmlessness H. Our framework demonstrates resilience against watermarking removal attacks, and it introduces limited latency through the blockchain fabric.<\/jats:p>","DOI":"10.3390\/fi17110490","type":"journal-article","created":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T04:26:29Z","timestamp":1761711989000},"page":"490","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["BIMW: Blockchain-Enabled Innocuous Model Watermarking for Secure Ownership Verification"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-2455-1586","authenticated-orcid":false,"given":"Xinyun","family":"Liu","sequence":"first","affiliation":[{"name":"Department of Applied Computing, Michigan Technological University, Houghton, MI 49931, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9623-237X","authenticated-orcid":false,"given":"Ronghua","family":"Xu","sequence":"additional","affiliation":[{"name":"Department of Applied Computing, Michigan Technological University, Houghton, MI 49931, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,10,26]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Liu, X., Xu, R., and Chen, Y. (2024). A Decentralized Digital Watermarking Framework for Secure and Auditable Video Data in Smart Vehicular Networks. Future Internet, 16.","DOI":"10.20944\/preprints202409.1228.v1"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1738","DOI":"10.1109\/JPROC.2019.2918951","article-title":"Edge intelligence: Paving the last mile of artificial intelligence with edge computing","volume":"107","author":"Zhou","year":"2019","journal-title":"Proc. IEEE"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"7457","DOI":"10.1109\/JIOT.2020.2984887","article-title":"Edge intelligence: The confluence of edge computing and artificial intelligence","volume":"7","author":"Deng","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"8099","DOI":"10.1109\/JIOT.2020.2996784","article-title":"Collaborate edge and cloud computing with distributed deep learning for smart city internet of things","volume":"7","author":"Wu","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"4665","DOI":"10.1109\/TII.2018.2842821","article-title":"Deep learning for smart industry: Efficient manufacture inspection system with fog computing","volume":"14","author":"Li","year":"2018","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Jia, R., Pei, H., Wang, W., Li, B., and Song, D. (2020, January 13\u201319). The secret revealer: Generative model-inversion attacks against deep neural networks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3551636","article-title":"A comprehensive survey on poisoning attacks and countermeasures in machine learning","volume":"55","author":"Tian","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"ref_8","unstructured":"Liang, Y., Xiao, J., Gan, W., and Yu, P.S. (2024). Watermarking techniques for large language models: A survey. arXiv."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Wang, R., Li, H., Mu, L., Ren, J., Guo, S., Liu, L., Fang, L., Chen, J., and Wang, L. (2022, January 10\u201314). Rethinking the vulnerability of dnn watermarking: Are watermarks robust against naturalness-aware perturbations?. Proceedings of the 30th ACM International Conference on Multimedia, Lisbon, Portugal.","DOI":"10.1145\/3503161.3548390"},{"key":"ref_10","unstructured":"Jia, H., Choquette-Choo, C.A., Chandrasekaran, V., and Papernot, N. (2021, January 11\u201313). Entangled watermarks as a defense against model extraction. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Online."},{"key":"ref_11","unstructured":"Yan, Y., Pan, X., Zhang, M., and Yang, M. (2023, January 9\u201311). Rethinking {White-Box} watermarks on deep learning models under neural structural obfuscation. Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA."},{"key":"ref_12","unstructured":"Adi, Y., Baum, C., Cisse, M., Pinkas, B., and Keshet, J. (2018, January 15\u201317). Turning your weakness into a strength: Watermarking deep neural networks by backdooring. Proceedings of the 27th USENIX Security Symposium (USENIX Security 18), Baltimore, MD, USA."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Shao, S., Li, Y., Yao, H., He, Y., Qin, Z., and Ren, K. (2024). Explanation as a watermark: Towards harmless and multi-bit model ownership verification via watermarking feature attribution. arXiv.","DOI":"10.14722\/ndss.2025.230338"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"135831","DOI":"10.1109\/ACCESS.2023.3335172","article-title":"Robust and secure medical image watermarking for edge-enabled e-healthcare","volume":"11","author":"Singh","year":"2023","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Liu, X., Xu, R., and Peng, X. (2025, January 12\u201314). BEWSAT: Blockchain-enabled watermarking for secure authentication and tamper localization in industrial visual inspection. Proceedings of the Eighth International Conference on Machine Vision and Applications (ICMVA 2025), Melbourne, Australia.","DOI":"10.1117\/12.3078474"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Xu, R., Liu, X., Nagothu, D., Qu, Q., and Chen, Y. (2025). Detecting Manipulated Digital Entities Through Real-World Anchors. Proceedings of the International Conference on Advanced Information Networking and Applications, Springer.","DOI":"10.1007\/978-3-031-87784-1_41"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Saha, A., Subramanya, A., and Pirsiavash, H. (2020, January 7\u201312). Hidden trigger backdoor attacks. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Li, E., Zhou, Z., and Chen, X. (2018, January 20). Edge intelligence: On-demand deep learning model co-inference with device-edge synergy. Proceedings of the 2018 Workshop on Mobile Edge Communications, New York, NY, USA.","DOI":"10.1145\/3229556.3229562"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Liu, X., Xu, R., and Zhao, C. (2024). AGFI-GAN: An Attention-Guided and Feature-Integrated Watermarking Model Based on Generative Adversarial Network Framework for Secure and Auditable Medical Imaging Application. Electronics, 14.","DOI":"10.20944\/preprints202411.1711.v1"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Boenisch, F. (2021). A systematic review on model watermarking for neural networks. Front. Big Data, 4.","DOI":"10.3389\/fdata.2021.729663"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Pan, X., Zhang, M., Yan, Y., Wang, Y., and Yang, M. (2023, January 6\u201310). Cracking white-box dnn watermarks via invariant neuron transforms. Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Long Beach, CA, USA.","DOI":"10.1145\/3580305.3599291"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"2318","DOI":"10.1109\/TIFS.2023.3265535","article-title":"Black-box dataset ownership verification via backdoor watermarking","volume":"18","author":"Li","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_23","first-page":"12058","article-title":"Dataset inference for self-supervised models","volume":"35","author":"Dziedzic","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"112230","DOI":"10.1109\/ACCESS.2022.3215660","article-title":"Blockchain and NFTs for trusted ownership, trading, and access of AI models","volume":"10","author":"Battah","year":"2022","journal-title":"IEEE Access"},{"key":"ref_25","unstructured":"Molnar, C. (2020). Interpretable Machine Learning, Lulu Press."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"22071","DOI":"10.1073\/pnas.1900654116","article-title":"Definitions, methods, and applications in interpretable machine learning","volume":"116","author":"Murdoch","year":"2019","journal-title":"Proc. Natl. Acad. Sci. USA"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., and Guestrin, C. (2016, January 13). \u201cWhy should i trust you?\u201d Explaining the predictions of any classifier. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939778"},{"key":"ref_28","unstructured":"Garreau, D., and Luxburg, U. (2020, January 26\u201328). Explaining the explainer: A first theoretical analysis of LIME. Proceedings of the International Conference on Artificial Intelligence and Statistics, PMLR, Online."},{"key":"ref_29","unstructured":"Benet, J. (2014). Ipfs-content addressed, versioned, p2p file system. arXiv."},{"key":"ref_30","unstructured":"(2025, October 22). Jetson Orin Nano Super Developer Kit. Available online: https:\/\/www.nvidia.com\/en-us\/autonomous-machines\/embedded-systems\/jetson-orin\/nano-super-developer-kit\/."},{"key":"ref_31","unstructured":"(2025, October 22). Solidity. Available online: https:\/\/docs.soliditylang.org\/en\/v0.8.13\/."},{"key":"ref_32","unstructured":"(2025, October 22). Ganache. Available online: https:\/\/archive.trufflesuite.com\/ganache\/."},{"key":"ref_33","unstructured":"(2025, October 22). Truffle. Available online: https:\/\/archive.trufflesuite.com\/docs\/truffle\/."},{"key":"ref_34","unstructured":"(2025, October 22). IPFS Docs. Available online: https:\/\/docs.ipfs.tech\/."},{"key":"ref_35","unstructured":"Krizhevsky, A., and Hinton, G. (2025, October 22). Convolutional deep belief networks on cifar-10. Available online: https:\/\/www.cs.toronto.edu\/~kriz\/conv-cifar10-aug2010.pdf."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., and Fei-Fei, L. (2009, January 20\u201325). Imagenet: A large-scale hierarchical image database. Proceedings of the 2009 IEEE Conference on Computer Vision and Pattern Recognition, Miami, FL, USA.","DOI":"10.1109\/CVPR.2009.5206848"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/11\/490\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T04:49:49Z","timestamp":1761713389000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/11\/490"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,26]]},"references-count":36,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2025,11]]}},"alternative-id":["fi17110490"],"URL":"https:\/\/doi.org\/10.3390\/fi17110490","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,26]]}}}