From: Secure neural network watermarking protocol against forging attack
N
L
Ï„
towner
tforged
10
38
36
3.4
100
20
18
0.4