Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

Dual-Locking Learned AI Models: A PIN-Based Sparse QIM Watermarking and Adaptive Index Permutation Approach

A dual-locking method for securing trained neural networks via key-driven index permutation and PIN-based Sparse QIM watermarking
Iva Vasic; Jesús Muñoz-Cádiz; Bata Vasic· 2026· DOI 10.48550/arXiv.2609.22981

The core problem

The proliferation of deep learning models has created an urgent need for mechanisms that protect both the intellectual property and the operational integrity of trained neural networks. Existing approaches to model security often address either encryption-based access control or watermarking for ownership verification, but rarely unify these goals in a single, recoverable framework. This paper proposes a dual-locking method that simultaneously locks a model against unauthorized use and embeds a blind, PIN-based watermark for authorship verification. The core idea is to combine cryptographic randomness—introduced through key-driven index permutation—with a robust watermark embedded via Sparse Quantization Index Modulation (QIM) into the bias coefficients. The method is designed to be reversible: without the correct key, the network's architecture remains intact but its internal representations are disrupted, causing severe accuracy degradation; with the correct key, the original model accuracy is fully restored. The authors motivate the work by highlighting the need for simultaneous model protection, recovery, and ownership verification, and they evaluate the approach across multipl

Innovation

The experiments demonstrate that the dual-locking method achieves strong protection and reliable recovery across diverse datasets and architectures. On MNIST, CIFAR-10/100, and ImageNet-1K, locking reduces accuracy below 10% for all tested models, and even below 0.5% for CNNs. For example, a ResNet CNN on CIFAR-10 that originally achieves over 90% accuracy drops to less than 0.5% when locked without the key. Similarly, transformer architectures on ImageNet-1K show accuracy degradation to below 10%. When the correct key is applied, the original model accuracy is fully restored, with no measurable loss. The embedded watermark remains imperceptible and enables blind verification of key association and model authorship. The watermark introduces no measurable accuracy degradation, as confirmed by comparing the performance of watermarked models with their non-watermarked counterparts. Analysis of embedding distributions across CNNs and transformers further indicates potential diagnostic value for identifying undertrained or suboptimally designed models. These results hold consistently across fully connected networks, ResNet CNNs, and transformers, demonstrating the generality of the appr
The proliferation of deep learning models has created an urgent need for mechanisms that protect both the intellectual property and the operational integrity of trained neural networks. Existing approaches to model security often address either encryption-based access control or watermarking for ownership verification, but rarely unify these goals in a single, recoverable framework. This paper proposes a dual-locking method that simultaneously locks a model against unauthorized use and embeds a blind, PIN-based watermark for authorship verification. The core idea is to combine cryptographic randomness—introduced through key-driven index permutation—with a robust watermark embedded via Sparse Quantization Index Modulation (QIM) into the bias coefficients. The method is designed to be reversible: without the correct key, the network's architecture remains intact but its internal representations are disrupted, causing severe accuracy degradation; with the correct key, the original model accuracy is fully restored. The authors motivate the work by highlighting the need for simultaneous model protection, recovery, and ownership verification, and they evaluate the approach across multiple datasets and architectures, including fully connected networks, ResNet CNNs, and transformers.
The proposed dual-locking framework consists of two complementary mechanisms: adaptive index permutation and PIN-based Sparse QIM watermarking.

Why it matters

The dual-locking approach offers a unified solution for model protection, recovery, and ownership verification. The combination of adaptive index permutation and PIN-based Sparse QIM watermarking ensures that unauthorized users cannot use the model effectively, while legitimate owners can fully recover it and verify their rights. The adaptive key selection strategy is crucial for maximizing degradation in the locked state without compromising recoverability. By redistributing high-magnitude weights to low-sensitivity positions, the method increases the impact of permutation on model performance, making it harder for attackers to reverse-engineer the model. The PIN-based watermarking provides a robust and blind mechanism for ownership verification, binding the model to a user-defined PIN. The watermark's imperceptibility and zero accuracy cost make it suitable for practical deployment. The observation that embedding distributions can reveal undertrained or suboptimally designed models suggests a diagnostic application beyond security. However, the paper does not discuss potential attacks such as fine-tuning or pruning that could remove the watermark, nor does it evaluate the method's robustness against adversarial attempts to recover the model without the key. Future work could explore these aspects and extend the approach to other model types and tasks. Overall, the proposed method represents a significant step toward comprehensive model security.

Who should read this

CS practitioners and researchers

Opening member content…