IP Library › Granted Patent US 12,541,576
Granted Patent B2
US 12,541,576 · App. 18/613,101 · Granted Feb 3, 2026

Method for digitally watermark a neural network, device and corresponding computer program

Inventors: Henri Belfy (Toulouse, FR); Tom Fougere (Toulouse, FR)
Assignee: THALES
G06F21/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,576
App. No.
18/613,101
Granted
Feb 3, 2026
Kind
B2
Abstract

A method of digitally watermarking a neural network, implemented by an electronic device, the neural network being stored within a data structure including blocks of parameters. The method includes, for a current parameter block consisting of at least N parameters representing real numbers, obtaining a message including N bits, at least N iterations of a parameter modification operation within the current block, including obtaining a current parameter, from among the at least N parameters of the current parameter block, and updating the value of a predetermined index bit of the current parameter as a function of a bit in the message.

Claims (24)

1 . A method of digital watermarking of a neural network, which method is implemented by an electronic device, said neural network being stored within a data structure consisting of blocks of parameters, the data structure comprising a current block of parameters, the current block of parameters comprising at least N parameters representing real numbers, the at least N parameters being selected from a group consisting of: layer weights, biases, tensor values, normalization values, and convolution values, the method comprising:

obtaining a message comprising N bits, the message taking the form of an encrypted character string constructed from a predetermined reference character string; and

at least N iterations of parameter modification within the current block of parameters, comprising:

obtaining a current parameter from the at least N parameters of the current parameter block of parameters; and

updating the value of a predetermined index bit of the current parameter as a function of a bit of the message.

2 . The method according to claim 1 , wherein said updating comprises calculating an operation or exclusively between a bit of a random vector of size N and a corresponding bit of the message.

3 . The method according to claim 1 , wherein the message is in the form of an encrypted code word.

4 . The method according to claim 1 , wherein said obtaining the message comprises:

obtaining a reference character string;

calculating a cyclic redundancy check code as a function of the reference character string, the cyclic check code being concatenated with the reference character string to form a code word; and

delivering an encrypted code word.

5 . The method according to claim 1 , wherein said obtaining the message further comprises at least one iteration of copying the encrypted code word within a character string in order to obtain the message of N bit length.

6 . The method according to claim 1 , wherein said obtaining the message comprises:

randomly selecting, within the current block, of a predetermined number K of most significant bits within a predetermined number of parameters of the current block delivering a characteristic binary image;

combining the characteristic binary image with a reference image, delivering a merged image; and

delivering the message, comprising further combining the merged image with a binary image obtained on the basis of a random draw of K bits.

7 . The method according to claim 6 , wherein said combining and said further combining each implement an operation or exclusively.

8 . An electronic device for a digital watermarking of a neural network, the neural network being recorded within a data structure comprising blocks of parameters, the data structure comprising a current block of parameters, the current block comprising at least N parameters representing real numbers, the at least N parameters being selected from a group consisting of: layer weights, biases, tensor values, normalization values, and convolution values, the device comprising:

means for obtaining a message comprising N bits, the message taking the form of an encrypted character string constructed from a predetermined reference character string; and

means for implementing at least N parameter modification iterations within the current block of parameters, comprising:

obtaining a current parameter from the at least N parameters of the current block of parameters; and

updating the value of a predetermined index bit of the current parameter as a function of a bit of the message.

9 . A non-transitory computer-readable medium including a computer program comprising instructions which, when executed by a programmable electronic device, cause the device to perform the digital watermarking method according to claim 1 .

10 . A non-transitory computer-readable medium storing a neural network, recorded within a data structure comprising blocks of parameters, the neural network being watermarked by the digital watermarking method according to claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: BELFY, HENRI; FOUGERE, TOM
To: THALES
Reel/Frame 066863/0113 →
Priority Claims (1)
FR 2303040 · Mar 29, 2023 · national
Continuity (1)
Related Publication 20240330416A1 · Oct 3, 2024
References Cited (18)
US 8892893B2 · Horne et al. · 2014 [cited by applicant]
US 10223780B2 · Tan · 2019 [cited by examiner]
US 10915809B2 · Krishnamoorthy · 2021 [cited by examiner]
US 11163860B2 · Gu · 2021 [cited by examiner]
US 11170793B2 · Jin · 2021 [cited by examiner]
US 11521043B2 · Uchida · 2022 [cited by examiner]
US 11575500B2 · Gomez · 2023 [cited by examiner]
US 11704765B2 · Kamath · 2023 [cited by examiner]
US 11972408B2 · Rouhani · 2024 [cited by examiner]
US 12014408B2 · Davis · 2024 [cited by examiner]
US 12260531B2 · Roulet · 2025 [cited by examiner]
US 12339937B1 · Wang · 2025 [cited by examiner]
WO 2023041212A1 · 2023 [cited by applicant]
Yue Li et al: “A survey of deep neural network watermarking techniques”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Mar. 16, 2021 (Mar. 16, 2021). [cited by applicant]
Reda Bellafqira et al: “DICTION: DynamIC robusT white box watermarking scheme”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Oct. 27, 2022 (Oct. 27, 2022). [cited by applicant]
“Securing Artificial Intelligence (SAI); Traceability of AI Models”, ETSI Draft Specification; SAI 010, European Telecommunications Standards Institute (ETSI), 650, Route Des Lucioles ; F-06921 Sophia-Antipolis ; France… [cited by applicant]
Mingfu Xue et al: “DNN Intellectual Property Protection: Taxonomy, Methods, Attack Resistance, and Evaluations”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Nov. 27, 2020… [cited by applicant]
FR 2303040, INPI Rapport de Recherche Preliminaire, Dec. 13, 2023, 3 pages. [cited by applicant]