LOCKEY: A Novel Approach to Model Authentication and Deepfake Tracking

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Singh, Mayank Kumar, Takahashi, Naoya, Liao, Wei-Hsiang, Mitsufuji, Yuki
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866914954282532864
author Singh, Mayank Kumar
Takahashi, Naoya
Liao, Wei-Hsiang
Mitsufuji, Yuki
author_facet Singh, Mayank Kumar
Takahashi, Naoya
Liao, Wei-Hsiang
Mitsufuji, Yuki
contents This paper presents a novel approach to deter unauthorized deepfakes and enable user tracking in generative models, even when the user has full access to the model parameters, by integrating key-based model authentication with watermarking techniques. Our method involves providing users with model parameters accompanied by a unique, user-specific key. During inference, the model is conditioned upon the key along with the standard input. A valid key results in the expected output, while an invalid key triggers a degraded output, thereby enforcing key-based model authentication. For user tracking, the model embeds the user's unique key as a watermark within the generated content, facilitating the identification of the user's ID. We demonstrate the effectiveness of our approach on two types of models, audio codecs and vocoders, utilizing the SilentCipher watermarking method. Additionally, we assess the robustness of the embedded watermarks against various distortions, validating their reliability in various scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2409_07743
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle LOCKEY: A Novel Approach to Model Authentication and Deepfake Tracking
Singh, Mayank Kumar
Takahashi, Naoya
Liao, Wei-Hsiang
Mitsufuji, Yuki
Cryptography and Security
This paper presents a novel approach to deter unauthorized deepfakes and enable user tracking in generative models, even when the user has full access to the model parameters, by integrating key-based model authentication with watermarking techniques. Our method involves providing users with model parameters accompanied by a unique, user-specific key. During inference, the model is conditioned upon the key along with the standard input. A valid key results in the expected output, while an invalid key triggers a degraded output, thereby enforcing key-based model authentication. For user tracking, the model embeds the user's unique key as a watermark within the generated content, facilitating the identification of the user's ID. We demonstrate the effectiveness of our approach on two types of models, audio codecs and vocoders, utilizing the SilentCipher watermarking method. Additionally, we assess the robustness of the embedded watermarks against various distortions, validating their reliability in various scenarios.
title LOCKEY: A Novel Approach to Model Authentication and Deepfake Tracking
topic Cryptography and Security
url https://arxiv.org/abs/2409.07743