Lattice-Quantization Identity Watermarking for Deep Neural Network Ownership Protection
Abstract
With the increasing trend of open-sourcing deep neural network (DNN) models, protecting model ownership has become a critical challenge, particularly in high-stakes domains such as medical AI. Existing backdoor-based watermarking methods suffer from two key limitations: visible trigger patterns and the lack of a reliable linkage to the model owner’s identity. In addition, many current verification schemes are often simplistic, relying mainly on task accuracy over trigger sets. To address these issues, we propose a novel lattice quantization-based backdoor watermarking framework for DNNs in black-box settings. The proposed method embeds the owner’s identity into trigger samples via lattice quantization index modulation, achieving identity encoding while maintaining trigger imperceptibility. Furthermore, we introduce an enhanced verification strategy that combines task performance with statistical identity extraction, providing more reliable ownership verification. Extensive experiments on benchmark datasets and multiple DNN architectures demonstrate that the proposed method achieves nearly 100% watermark success rate (WSR) and over 91% identity extraction success rate (ESR), with benign accuracy degradation below 1.51%, validating its effectiveness for reliable DNN ownership verification in black-box settings.