TIST Journal 2026 Journal Article
Delete but Not Gone: Reactivation of Neural Network Watermarks
- Hewang Nie
- Jue Xiao
- Zhi Lu
- Renfei Shen
- Songfeng Lu
As Deep Neural Networks (DNNs) become integral to critical applications, protecting their Intellectual Property (IP) has become paramount. Neural network watermarking is a technique that embeds unique identifiers into models, asserting ownership and deterring unauthorized use. However, sophisticated attacks can deactivate or remove these watermarks without significantly compromising model performance, undermining current protection strategies. In this article, we introduce the first method for reactivating deactivated neural network watermarks in altered DNN models without requiring access to the original model parameters or training data. By formulating the reactivation process as an optimization problem, we employ projected gradient descent to identify new trigger inputs that restore the embedded watermark. Regularization techniques are incorporated to ensure these triggers resemble legitimate inputs, enhancing both stealth and practicality. Through experiments on various benchmark datasets and model architectures, we demonstrate the effectiveness of our method against common model alterations, including fine-tuning, pruning, and surrogate model attacks. Our work addresses a critical gap in DNN IP protection, offering a robust and practical solution for watermark reactivation. This empowers model owners to assert their rights even in the face of advanced adversarial tactics.