Research Article

TADW: Traceable and Anti-detection Dynamic Watermarking of Deep Neural Networks

Figure 2

The workflow of extracting SN. “Y” denotes that the query class of a sample is the same as its original class. “N” denotes they are different. “Num(Y)” denotes the count of “Y.”