Trigger-based watermarking aims to protect the intellectual property of machine learning models by embedding abnormal behavior that is activated only on specific trigger inputs, while preserving performance on standard test data. Although widely studied, current approaches to trigger-based watermarking remain largely informal and empirical. In this work, we introduce a formal framework for reasoning about the security of trigger-based watermarking, and we propose rigorous security definitions to evaluate existing schemes. Our analysis reveals that many schemes rely on underspecified parameters and flawed design assumptions. Notably, we demonstrate that different security goals in watermarking can be in tension with one another, and achieving a balance among them requires careful design. Our principled analysis offers a way to resolve this tension in practice. Experiments on existing schemes and public datasets corroborate the relevance of our theoretical findings.

Formal Foundations of Trigger-Based Watermarking

Calzavara S.;Cazzaro L.;Lucchese C.;Orlando S.
2026

Abstract

Trigger-based watermarking aims to protect the intellectual property of machine learning models by embedding abnormal behavior that is activated only on specific trigger inputs, while preserving performance on standard test data. Although widely studied, current approaches to trigger-based watermarking remain largely informal and empirical. In this work, we introduce a formal framework for reasoning about the security of trigger-based watermarking, and we propose rigorous security definitions to evaluate existing schemes. Our analysis reveals that many schemes rely on underspecified parameters and flawed design assumptions. Notably, we demonstrate that different security goals in watermarking can be in tension with one another, and achieving a balance among them requires careful design. Our principled analysis offers a way to resolve this tension in practice. Experiments on existing schemes and public datasets corroborate the relevance of our theoretical findings.
2026
Proceedings - 11th European Symposium on Security and Privacy, EuroS and P 2026
File in questo prodotto:
File Dimensione Formato  
eurosp26.pdf

embargo fino al 06/07/2028

Tipologia: Documento in Post-print
Licenza: Accesso gratuito (solo visione)
Dimensione 592.19 kB
Formato Adobe PDF
592.19 kB Adobe PDF   Visualizza/Apri

I documenti in ARCA sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10278/5124728
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact