{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T18:31:12Z","timestamp":1772303472159,"version":"3.50.1"},"reference-count":21,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2022,5,4]],"date-time":"2022-05-04T00:00:00Z","timestamp":1651622400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61602491"],"award-info":[{"award-number":["61602491"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>In recent years, the wide application of deep neural network models has brought serious risks of intellectual property rights infringement. Embedding a watermark in a network model is an effective solution to protect intellectual property rights. Although researchers have proposed schemes to add watermarks to models, they cannot prevent attackers from adding and overwriting original information, and embedding rates cannot be quantified. Therefore, aiming at these problems, this paper designs a high embedding rate and tamper-proof watermarking scheme. We employ wet paper coding (WPC), in which important parameters are regarded as wet blocks and the remaining unimportant parameters are regarded as dry blocks in the model. To obtain the important parameters more easily, we propose an optimized probabilistic selection strategy (OPSS). OPSS defines the unimportant-level function and sets the importance threshold to select the important parameter positions and to ensure that the original function is not affected after the model parameters are changed. We regard important parameters as an unmodifiable part, and only modify the part that includes the unimportant parameters. We selected the MNIST, CIFAR-10, and ImageNet datasets to test the performance of the model after adding a watermark and to analyze the fidelity, robustness, embedding rate, and comparison schemes of the model. Our experiment shows that the proposed scheme has high fidelity and strong robustness along with a high embedding rate and the ability to prevent malicious tampering.<\/jats:p>","DOI":"10.3390\/s22093489","type":"journal-article","created":{"date-parts":[[2022,5,4]],"date-time":"2022-05-04T08:21:25Z","timestamp":1651652485000},"page":"3489","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Wet Paper Coding-Based Deep Neural Network Watermarking"],"prefix":"10.3390","volume":"22","author":[{"given":"Xuan","family":"Wang","sequence":"first","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8502-9907","authenticated-orcid":false,"given":"Yuliang","family":"Lu","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuehu","family":"Yan","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Long","family":"Yu","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,5,4]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Ribeiro, M., Grolinger, K., and Capretz, M.A. (2015, January 9\u201311). MLaaS: Machine Learning as a Service. Proceedings of the 2015 IEEE 14th International Conference on Machine Learning and Applications (ICMLA), Miami, FL, USA.","DOI":"10.1109\/ICMLA.2015.152"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Boenisch, F. (2020). A Survey on Model Watermarking Neural Networks. arXiv.","DOI":"10.3389\/fdata.2021.729663"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Uchida, Y., Nagai, Y., Sakazawa, S., and Satoh, S.I. (2017, January 6\u20139). Embedding Watermarks into Deep Neural Networks. Proceedings of the 2017 ACM on International Conference on Multimedia Retrieval, Bucharest, Romania.","DOI":"10.1145\/3078971.3078974"},{"key":"ref_4","unstructured":"Fan, L., Ng, K.W., and Chan, C.S. (2019, January 8\u201314). Rethinking Deep Neural Network Ownership Verification: Embedding Passports to Defeat Ambiguity Attacks. Proceedings of the Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, Vancouver, BC, Canada."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Feng, L., and Zhang, X. (2020, January 6\u20138). Watermarking neural network with compensation mechanism. Proceedings of the International Conference on Knowledge Science, Engineering and Management, Singapore.","DOI":"10.1007\/978-3-030-55393-7_33"},{"key":"ref_6","unstructured":"Zhang, J., Chen, D., Liao, J., Fang, H., Zhang, W., Zhou, W., Cui, H., and Yu, N. (2020, January 5\u20137). Model watermarking for image processing networks. Proceedings of the AAAI Conference on Artificial Intelligence, Halkidiki, Greece."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Darvish Rouhani, B., Chen, H., and Koushanfar, F. (2019). Deepsigns: An end G to G end watermarking framework for owner ship protection of deep neural networks. Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems, Providence, RI, USA, 13\u201317 April 2019, ACM.","DOI":"10.1145\/3297858.3304051"},{"key":"ref_8","first-page":"964","article-title":"Research Progress of Neural Networks Watermarking Technology","volume":"58","author":"Zhang","year":"2021","journal-title":"J. Comput. Res. Dev."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Zhong, Q., Zhang, L.Y., Zhang, J., Gao, L., and Xiang, Y. (2020, January 11\u201314). Protecting IP of deep neural networks with watermarking: A newlabel helps. Proceedings of the Pacific-Asia Conference on Knowledge Discovery and Data Mining, Singapore.","DOI":"10.1007\/978-3-030-47436-2_35"},{"key":"ref_10","first-page":"228","article-title":"Robust Watermarking of Neural Network with Exponential Weighting","volume":"Volume 2","author":"Namba","year":"2019","journal-title":"Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, Auckland, New Zeland, 7\u201312 July 2019"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Szyller, S., Atli, B.G., Marchal, S., and Asokan, N. (2020). DAWN: Dynamic Adversarial Watermarking of Neural Networks. arXiv.","DOI":"10.1145\/3474085.3475591"},{"key":"ref_12","unstructured":"Cai, F. (2020, August 20). \u201cHack\u201d the Neural Network: Tencent Reveals New AI Attack Methods. (In Chinese)."},{"key":"ref_13","unstructured":"Neeta, D., Snehal, K., and Jacobs, D. (2006, January 6). Implementation of LSB Steganography and Its Evaluation for Various Bits. Proceedings of the International Conference on Digital Information Management, Bangalore, India."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Wang, Z., Liu, C., and Cui, X. (2021, January 5\u20138). EvilModel: Hiding Malware Inside of Neural Network Models. Proceedings of the 2021 IEEE Symposium on Computers and Communications (ISCC), Athens, Greece.","DOI":"10.1109\/ISCC53001.2021.9631425"},{"key":"ref_15","unstructured":"Simonyan, K., and Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Li, Y., Lin, S., Zhang, B., Liu, J., Doermann, D., Wu, Y., Huang, F., and Ji, R. (2019, January 15\u201320). Exploiting kernel sparsity and entropy for interpretable cnn compression. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00291"},{"key":"ref_18","unstructured":"Morcos, A.S., Barrett, D.G., Rabinowitz, N.C., and Botvinick, M. (2018). On the importance of single directions for generalization. arXiv."},{"key":"ref_19","unstructured":"Shrikumar, A., Greenside, P., and Kundaje, A. (2017, January 6\u201311). Learning important features through propagating activation differences. Proceedings of the International Conference on Machine Learning (PMLR), Sydney, Australia."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Yu, R., Li, A., Chen, C.F., Lai, J.H., Morariu, V.I., Han, X., Gao, M., Lin, C.Y., and Davis, L.S. (2018, January 18\u201323). Nisp: Pruning networks using neuron importance score propagation. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00958"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Tian, J., Zhou, J., and Duan, J. (2021, January 20\u201325). Probabilistic selective encryption of convolutional neural networks for hierarchical services. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Nashville, TN, USA.","DOI":"10.1109\/CVPR46437.2021.00224"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/9\/3489\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:05:54Z","timestamp":1760137554000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/9\/3489"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,4]]},"references-count":21,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2022,5]]}},"alternative-id":["s22093489"],"URL":"https:\/\/doi.org\/10.3390\/s22093489","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,5,4]]}}}