Revisiting the Information Capacity of Neural Network Watermarks: Upper
Bound Estimation and Beyond
Revisiting the Information Capacity of Neural Network Watermarks: Upper
Bound Estimation and Beyond
To trace the copyright of deep neural networks, an owner can embed its identity information into its model as a watermark. The capacity of the watermark quantify the maximal volume of information that can be verified from the watermarked model. Current studies on capacity focus on the ownership verification accuracy …