Abstract:With the successful application of deep neural networks (DNN) in many fields, deep model intellectual property protection technologies represented by neural network watermarking have received widespread attention in recent years. An overview of existing DNN model watermarking methods was provided in this paper. According to the different conditions required for extracting watermarks, watermarks were classified into three categories: white-box watermarking, black-box watermarking, and box-free watermarking. Furthermore, various methods were categorized according to different watermark embedding mechanisms or applicable model objects, and an in-depth analysis was conducted on the main principles, implementation approaches, and development trends of these methods. Subsequently, a systematic summary and classification of attack methods on model watermarking were provided, revealing the main threats and security issues faced by neural network watermarking. On this basis, performance comparison and analysis were conducted on representative methods in each category of model watermarks, which clarified their advantages and disadvantages to help researchers choose appropriate watermark methods based on actual application scenarios. Finally, the challenges of current deep neural network model watermarking were discussed, and potential future research directions were envisioned to provide references for related research.