{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,21]],"date-time":"2025-10-21T15:50:50Z","timestamp":1761061850777,"version":"build-2065373602"},"reference-count":48,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2023,6,20]],"date-time":"2023-06-20T00:00:00Z","timestamp":1687219200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Natural Science Foundation of China (NSFC)","award":["U22B2047","U1936214"],"award-info":[{"award-number":["U22B2047","U1936214"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Natural language generation (NLG) models combined with increasingly mature and powerful deep learning techniques have been widely used in recent years. Deployed NLG models in practical applications may be stolen or used illegally, and watermarking has become an important tool to protect the Intellectual Property (IP) of these deep models. Watermarking technique designs algorithms to embed watermark information and extracts watermark information for IP identification of NLG models can be seen as a symmetric signal processing problem. In terms of IP protection of NLG models, however, the existing watermarking approaches cannot provide reliable and timely model protection and prevent illegal users from utilizing the original performance of the stolen models. In addition, the quality of watermarked text sequences generated by some watermarking approaches is not high. In view of these, this paper proposes two embedding schemes to the hidden memory state of the RNN to protect the IP of NLG models for different tasks. Besides, we add a language model loss to the model decoder to improve the grammatical correctness of the output text sequences. During the experiments, it is proved that our approach does not compromise the performance of the original NLG models on the corresponding datasets and outputs high-quality text sequences, while forged secret keys will generate unusable NLG models, thus defeating the purpose of model infringement. Besides, we also conduct sufficient experiments to prove that the proposed model has strong robustness under different attacks.<\/jats:p>","DOI":"10.3390\/sym15061287","type":"journal-article","created":{"date-parts":[[2023,6,20]],"date-time":"2023-06-20T02:26:56Z","timestamp":1687228016000},"page":"1287","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["An Effective Framework for Intellectual Property Protection of NLG Models"],"prefix":"10.3390","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2989-2669","authenticated-orcid":false,"given":"Mingjie","family":"Li","sequence":"first","affiliation":[{"name":"School of Communication and Information Engineering, Shanghai University, Shanghai 200444, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0283-5338","authenticated-orcid":false,"given":"Zichi","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Communication and Information Engineering, Shanghai University, Shanghai 200444, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinpeng","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Communication and Information Engineering, Shanghai University, Shanghai 200444, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,6,20]]},"reference":[{"key":"ref_1","first-page":"1","article-title":"Adversarial attacks on deep-learning models in natural language processing: A survey","volume":"11","author":"Zhang","year":"2020","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"doi-asserted-by":"crossref","unstructured":"Mittal, V., Gangodkar, D., and Pant, B. (2020, January 6\u20137). Exploring The Dimension of DNN Techniques For Text Categorization Using NLP. Proceedings of the 2020 6th International Conference on Advanced Computing and Communication Systems (ICACCS), Coimbatore, India.","key":"ref_2","DOI":"10.1109\/ICACCS48705.2020.9074228"},{"key":"ref_3","first-page":"1","article-title":"Deep learning for natural language processing in urology: State-of-the-art automated extraction of detailed pathologic prostate cancer data from narratively written electronic health records","volume":"2","author":"Tian","year":"2018","journal-title":"JCO Clin. Cancer Inform."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1983","DOI":"10.1109\/TASE.2020.3028151","article-title":"Condition-based monitoring in variable machine running conditions using low-level knowledge transfer with DNN","volume":"18","author":"Maurya","year":"2020","journal-title":"IEEE Trans. Autom. Sci. Eng."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"275","DOI":"10.1177\/1063293X211025105","article-title":"Breast cancer diagnosis using multiple activation deep neural network","volume":"29","author":"Vijayakumar","year":"2021","journal-title":"Concurr. Eng."},{"key":"ref_6","first-page":"9237","article-title":"A framework combining DNN and level-set method to segment brain tumor in multi-modalities MR image","volume":"23","author":"Qin","year":"2019","journal-title":"J. Abbr."},{"unstructured":"Xiang, T., Xie, C., Guo, S., Li, J., and Zhang, T. (2021). Protecting Your NLG Models with Semantic and Robust Watermarks. arXiv.","key":"ref_7"},{"doi-asserted-by":"crossref","unstructured":"Wallace, E., Stern, M., and Song, D. (2020, January 16\u201320). Imitation Attacks and Defenses for Black-box Machine Translation Systems. Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP), Online.","key":"ref_8","DOI":"10.18653\/v1\/2020.emnlp-main.446"},{"unstructured":"Krishna, K., Tomar, G.S., and Parikh, A.P. (2019, January 6\u20139). Thieves on Sesame Street! Model Extraction of BERT-based APIs. Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA.","key":"ref_9"},{"doi-asserted-by":"crossref","unstructured":"He, X., Lyu, L., Xu, Q., and Sun, L. (2021, January 6\u201311). Model Extraction and Adversarial Transferability. Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Mexico City, Mexico.","key":"ref_10","DOI":"10.18653\/v1\/2021.naacl-main.161"},{"doi-asserted-by":"crossref","unstructured":"Uchida, Y., Nagai, Y., Sakazawa, S., and Satoh, S. (2017, January 6\u20139). Embedding Watermarks into Deep Neural Networks. Proceedings of the 2017 Acm on International Conference on Multimedia Retrieval, Bucharest, Romania.","key":"ref_11","DOI":"10.1145\/3078971.3078974"},{"doi-asserted-by":"crossref","unstructured":"Zhang, J., Gu, Z., Jang, J., Wu, H., Stoecklin, M.P., Huang, H., and Molloy, I. (2018, January 4\u20138). Protecting Intellectual Property of Deep Neural Networks with Watermarking. Proceedings of the 2018 on Asia Conference on Computer and Communications Security, Incheon, Republic of Korea.","key":"ref_12","DOI":"10.1145\/3196494.3196550"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"6122","DOI":"10.1109\/TPAMI.2021.3088846","article-title":"DeepIP: Deep Neural Network Intellectual Property Protection with Passports","volume":"44","author":"Fan","year":"2021","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"2591","DOI":"10.1109\/TCSVT.2020.3030671","article-title":"Watermarking Neural Networks with Watermarked Images","volume":"31","author":"Wu","year":"2020","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"108285","DOI":"10.1016\/j.patcog.2021.108285","article-title":"Protect, show, attend and tell: Empowering image captioning models with ownership protection","volume":"122","author":"Lim","year":"2022","journal-title":"Pattern Recogn."},{"unstructured":"Chen, X., Salem, A., Backes, M., Ma, S., and Zhang, Y. (2021, January 24). Badnl: Backdoor attacks against nlp models. Proceedings of the ICML 2021 Workshop on Adversarial Machine Learning, Virtual Event, China.","key":"ref_16"},{"doi-asserted-by":"crossref","unstructured":"Shen, L., Ji, S., Zhang, X., and Li, J. (2021, January 15\u201319). Backdoor Pre-trained Models Can Transfer to All. Proceedings of the Conference on Computer and Communications Security, Virtual Event, Republic of Korea.","key":"ref_17","DOI":"10.1145\/3460120.3485370"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"138872","DOI":"10.1109\/ACCESS.2019.2941376","article-title":"A backdoor attack against lstm-based text classification systems","volume":"7","author":"Dai","year":"2019","journal-title":"IEEE Access"},{"doi-asserted-by":"crossref","unstructured":"He, X., Xu, Q., Lyu, L., Wu, F., and Wang, C. (2022). Protecting intellectual property of language generation apis with lexical watermark. Proc. AAAI Conf. Artif. Intell., 10758\u201310766.","key":"ref_19","DOI":"10.1609\/aaai.v36i10.21321"},{"unstructured":"He, X., Xu, Q., Zeng, Y., Lyu, L., Wu, F., Li, J., and Jia, R. (December, January 28). CATER: Intellectual Property Protection on Text Generation APIs via Conditional Watermarks. Proceedings of the 36th Conference on Neural Information Processing Systems, New Orleans, LA, USA.","key":"ref_20"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"8011","DOI":"10.1109\/ACCESS.2018.2796585","article-title":"A review of text watermarking: Theory, methods, and applications","volume":"6","author":"Kamaruddin","year":"2018","journal-title":"IEEE Access"},{"key":"ref_22","first-page":"29","article-title":"An existential review on text watermarking techniques","volume":"120","author":"Kaur","year":"2015","journal-title":"Int. J. Comput. Appl."},{"key":"ref_23","first-page":"165","article-title":"A survey of digital watermarking techniques, applications and attacks","volume":"2","author":"Singh","year":"2013","journal-title":"Int. J. Eng. Innov. Technol. (IJEIT)"},{"unstructured":"Adi, Y., Baum, C., Cisse, M., Pinkas, B., and Keshet, J. (2018, January 15\u201317). Turning your weakness into a strength: Watermarking deep neural networks by backdooring. Proceedings of the 27th USENIX Security Symposium (USENIX Security 18), Baltimore, MD, USA.","key":"ref_24"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"9233","DOI":"10.1007\/s00521-019-04434-z","article-title":"Adversarial frontier stitching for remote neural network watermarking","volume":"32","author":"Perez","year":"2020","journal-title":"Neural Comput. Appl."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1852","DOI":"10.1109\/TNNLS.2020.2991378","article-title":"Watermarking deep neural networks in image processing","volume":"32","author":"Quan","year":"2020","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"doi-asserted-by":"crossref","unstructured":"Darvish Rouhani, B., Chen, H., and Koushanfar, F. (2019, January 13\u201317). Deepsigns: An end-to-end watermarking framework for ownership protection of deep neural networks. Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems, Providence, RI, USA.","key":"ref_27","DOI":"10.1145\/3297858.3304051"},{"unstructured":"Vaswani, A., Shazeer, N., and Parmar, N. (2017, January 4\u20139). Attention is all you need. Proceedings of the Advances in Neural Information Processing Systems, Long Beach, CA, USA.","key":"ref_28"},{"unstructured":"Shetty, R., Schiele, B., and Fritz, M. (2018, January 15\u201317). A4nt: Author attribute anonymity by adversarial training of neural machine translation. Proceedings of the 27th USENIX Security Symposium (USENIX Security 18), Baltimore, MD, USA.","key":"ref_29"},{"unstructured":"Merity, S., Keskar, N.S., and Socher, R. (May, January 30). Regularizing and optimizing lstm language models. Proceedings of the International Conference on Learning Representations (ICLR), Vancouver, BC, Canada.","key":"ref_30"},{"doi-asserted-by":"crossref","unstructured":"Howard, J., and Ruder, S. (2018, January 15\u201320). Universal language model fine-tuning for text classification. Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics (ACL), Melbourne, Australia.","key":"ref_31","DOI":"10.18653\/v1\/P18-1031"},{"unstructured":"Dai, Z., Yang, Z., Yang, Y., Carbonell, J.G., Le, Q., and Salakhutdinov, R. (August, January 28). Transformer-xl: Attentive language models beyond a fixed-length context. Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics (ACL), Florence, Italy.","key":"ref_32"},{"unstructured":"Carlini, N., Liu, C., Erlingsson, U., Kos, J., and Song, D. (2019, January 14\u201316). The secret sharer: Evaluating and testing unintended memorization in neural networks. Proceedings of the 28th USENIX Security Symposium (USENIX Security 19), Santa Clara, CA, USA.","key":"ref_33"},{"doi-asserted-by":"crossref","unstructured":"Koehn, P., Hoang, H., and Birch, A. (2007, January 24\u201329). Moses: Open source toolkit for statistical machine translation. Proceedings of the 45th Annual Meeting of the Association for Computational Linguistics Companion Volume Proceedings of the Demo and Poster Sessions, Prague, Czech Republic.","key":"ref_34","DOI":"10.3115\/1557769.1557821"},{"doi-asserted-by":"crossref","unstructured":"Karpathy, A., and Li, F.-F. (2015, January 7\u201312). Deep visual-semantic alignments for generating image descriptions. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Boston, MA, USA.","key":"ref_35","DOI":"10.1109\/CVPR.2015.7298932"},{"unstructured":"See, A., Liu, P.J., and Manning, C.D. (August, January 30). Get to the point: Summarization with pointer-generator networks. Proceedings of the 55th Annual Meeting of the Association for Computational Linguistics, Vancouver, BC, Canada.","key":"ref_36"},{"doi-asserted-by":"crossref","unstructured":"Szyller, S., Atli, B.G., Marchal, S., and Asokan, N. (2021, January 20\u201324). Dawn: Dynamic adversarial watermarking of neural networks. Proceedings of the 29th ACM International Conference on Multimedia, Virtual Event, China.","key":"ref_37","DOI":"10.1145\/3474085.3475591"},{"unstructured":"Bahdanau, D., Cho, K., and Bengio, Y. (2014, January 14\u201316). Neural machine translation by jointly learning to align and translate. Proceedings of the 2nd International Conference on Learning Representations (ICLR 2014), Banff, AB, Canada.","key":"ref_38"},{"unstructured":"Xu, K., Ba, J., Kiros, R., and Cho, K. (2015, January 6\u201311). Show, attend and tell: Neural image caption generation with visual attention. Proceedings of the International Conference on Machine Learning, Lille, France.","key":"ref_39"},{"doi-asserted-by":"crossref","unstructured":"Nallapati, R., Zhou, B., Gulcehre, C., and Xiang, B. (2016, January 11\u201312). Abstractive Text Summarization using Sequence-to-sequence RNNs and Beyond. Proceedings of the Conference on Computational Natural Language Learning (CoNLL 2016), Berlin, Germany.","key":"ref_40","DOI":"10.18653\/v1\/K16-1028"},{"unstructured":"Zeiler, M.D. (2012). ADADELTA: An adaptive learning rate method. arXiv.","key":"ref_41"},{"doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","key":"ref_42","DOI":"10.1109\/CVPR.2016.90"},{"unstructured":"Kingma, D.P., and Ba, J. (2015, January 7\u20139). Adam: A method for stochastic optimization. Proceedings of the International Conference on Learning Representations (ICLR), San Diego, CA, USA.","key":"ref_43"},{"doi-asserted-by":"crossref","unstructured":"Papineni, K., Roukos, S., and Ward, T. (2002, January 6\u201312). Bleu: A method for automatic evaluation of machine translation. Proceedings of the 40th Annual Meeting of the Association for Computational Linguistics, Philadelphia, PA, USA.","key":"ref_44","DOI":"10.3115\/1073083.1073135"},{"doi-asserted-by":"crossref","unstructured":"Li, D., Zhang, Y., and Peng, H. (2021, January 6\u201313). Contextualized perturbation for textual adversarial attack. Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics, Online.","key":"ref_45","DOI":"10.18653\/v1\/2021.naacl-main.400"},{"unstructured":"Anderson, P., Fernando, B., and Johnson, M. (2016). European Conference on Computer Vision, Springer.","key":"ref_46"},{"unstructured":"Lin, C.Y. (2004). Text Summarization Branches Out, Association for Computational Linguistics.","key":"ref_47"},{"doi-asserted-by":"crossref","unstructured":"See, A., Luong, M.-T., and Manning, C.D. (2016). Compression of neural machine translation models via pruning. arXiv.","key":"ref_48","DOI":"10.18653\/v1\/K16-1029"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/15\/6\/1287\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:56:57Z","timestamp":1760126217000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/15\/6\/1287"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,20]]},"references-count":48,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2023,6]]}},"alternative-id":["sym15061287"],"URL":"https:\/\/doi.org\/10.3390\/sym15061287","relation":{},"ISSN":["2073-8994"],"issn-type":[{"type":"electronic","value":"2073-8994"}],"subject":[],"published":{"date-parts":[[2023,6,20]]}}}