{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:24:10Z","timestamp":1742912650809,"version":"3.40.3"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031365737"},{"type":"electronic","value":"9783031365744"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-36574-4_3","type":"book-chapter","created":{"date-parts":[[2023,7,15]],"date-time":"2023-07-15T13:01:58Z","timestamp":1689426118000},"page":"34-57","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Can Image Watermarking Efficiently Protect Deep-Learning-Based Image Classifiers? \u2013 A Preliminary Security Analysis of an IP-Protecting Method"],"prefix":"10.1007","author":[{"given":"Jia-Hui","family":"Xie","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Di","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo-Hao","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hai","family":"Su","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huan","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,7,16]]},"reference":[{"unstructured":"ImageNet Classification. https:\/\/pjreddie.com\/darknet\/imagenet\/","key":"3_CR1"},{"unstructured":"Models and Pre-Trained Weights \u2013 Torchvision 0.12 Documentations (2017). https:\/\/pytorch.org\/vision\/stable\/models.html","key":"3_CR2"},{"doi-asserted-by":"publisher","unstructured":"Aiken, W., Kim, H., Woo, S., Ryoo, J.: Neural network laundering: removing black-box backdoor watermarks from deep neural networks. Comput. Secur. 106, 102277 (2021). https:\/\/doi.org\/10.1016\/j.cose.2021.102277","key":"3_CR3","DOI":"10.1016\/j.cose.2021.102277"},{"unstructured":"Baluja, S.: Hiding images in plain sight: deep steganography. In: Proceedings of the 31st International Conference on Neural Information Processing Systems, NIPS 2017, pp. 2066\u20132076. Curran Associates Inc., Red Hook, NY, USA (2017)","key":"3_CR4"},{"issue":"7","key":"3_CR5","doi-asserted-by":"publisher","first-page":"1685","DOI":"10.1109\/TPAMI.2019.2901877","volume":"42","author":"S Baluja","year":"2020","unstructured":"Baluja, S.: Hiding images within images. IEEE Trans. Pattern Anal. Mach. Intell. 42(7), 1685\u20131697 (2020). https:\/\/doi.org\/10.1109\/TPAMI.2019.2901877","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"unstructured":"Batina, L., Bhasin, S., Jap, D., Picek, S.: CSI NN: reverse engineering of neural network architectures through electromagnetic side channel. In: 28th USENIX Security Symposium (USENIX Security 2019), pp. 515\u2013532. USENIX Association, Santa Clara, CA (2019). https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/batina","key":"3_CR6"},{"issue":"5","key":"3_CR7","doi-asserted-by":"publisher","first-page":"1181","DOI":"10.1109\/TIFS.2018.2871749","volume":"14","author":"M Boroumand","year":"2019","unstructured":"Boroumand, M., Chen, M., Fridrich, J.: Deep residual network for steganalysis of digital images. IEEE Trans. Inf. Forensics Secur. 14(5), 1181\u20131193 (2019). https:\/\/doi.org\/10.1109\/TIFS.2018.2871749","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"doi-asserted-by":"publisher","unstructured":"Cao, X., Jia, J., Gong, N.Z.: IPGuard: protecting intellectual property of deep neural networks via fingerprinting the classification boundary. In: Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, ASIA CCS 2021, pp. 14\u201325. Association for Computing Machinery, New York, NY, USA (2021). https:\/\/doi.org\/10.1145\/3433210.3437526","key":"3_CR8","DOI":"10.1145\/3433210.3437526"},{"doi-asserted-by":"publisher","unstructured":"Chen, J., et al.: Copy, Right? A testing framework for copyright protection of deep learning models. cs.CR abs\/2112.05588 (2021). https:\/\/doi.org\/10.48550\/ARXIV.2112.05588","key":"3_CR9","DOI":"10.48550\/ARXIV.2112.05588"},{"doi-asserted-by":"publisher","unstructured":"Chen, K., Guo, S., Zhang, T., Xie, X., Liu, Y.: Stealing deep reinforcement learning models for fun and profit. In: Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, ASIA CCS 2021, pp. 307\u2013319. Association for Computing Machinery, New York, NY, USA (2021). https:\/\/doi.org\/10.1145\/3433210.3453090","key":"3_CR10","DOI":"10.1145\/3433210.3453090"},{"doi-asserted-by":"publisher","unstructured":"Chen, X., et al.: Recent advances and clinical applications of deep learning in medical image analysis. Med. Image Anal. 102444 (2022). (in Press). https:\/\/doi.org\/10.1016\/j.media.2022.102444","key":"3_CR11","DOI":"10.1016\/j.media.2022.102444"},{"key":"3_CR12","doi-asserted-by":"publisher","first-page":"102313","DOI":"10.1016\/j.media.2021.102313","volume":"76","author":"J Cheng","year":"2022","unstructured":"Cheng, J., et al.: ResGANet: residual group attention network for medical image classification and segmentation. Med. Image Anal. 76, 102313 (2022). https:\/\/doi.org\/10.1016\/j.media.2021.102313","journal-title":"Med. Image Anal."},{"key":"3_CR13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TPAMI.2021.3088846","volume":"44","author":"L Fan","year":"2021","unstructured":"Fan, L., Ng, K.W., Chan, C.S., Yang, Q.: DeepIP: deep neural network intellectual property protection with passports. IEEE Trans. Pattern Anal. Mach. Intell. 44, 1 (2021). https:\/\/doi.org\/10.1109\/TPAMI.2021.3088846","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2016)","key":"3_CR14","DOI":"10.1109\/CVPR.2016.90"},{"doi-asserted-by":"publisher","unstructured":"Hilty, R., Hoffmann, J., Scheuerer, S.: Intellectual property justification for artificial intelligence. Artif. Intell. Intellect. Property (2021). https:\/\/doi.org\/10.1093\/oso\/9780198870944.003.0004","key":"3_CR15","DOI":"10.1093\/oso\/9780198870944.003.0004"},{"issue":"10","key":"3_CR16","doi-asserted-by":"publisher","first-page":"2585","DOI":"10.1007\/s10115-021-01605-0","volume":"63","author":"X Hu","year":"2021","unstructured":"Hu, X., Chu, L., Pei, J., Liu, W., Bian, J.: Model complexity of deep learning: a survey. Knowl. Inf. Syst. 63(10), 2585\u20132619 (2021). https:\/\/doi.org\/10.1007\/s10115-021-01605-0","journal-title":"Knowl. Inf. Syst."},{"doi-asserted-by":"crossref","unstructured":"Jing, J., Deng, X., Xu, M., Wang, J., Guan, Z.: HiNet: deep image hiding by invertible network. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV), pp. 4733\u20134742 (2021)","key":"3_CR17","DOI":"10.1109\/ICCV48922.2021.00469"},{"unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images. Technical report (2009)","key":"3_CR18"},{"doi-asserted-by":"publisher","unstructured":"Li, Z., Hu, C., Zhang, Y., Guo, S.: How to prove your model belongs to you: a blind-watermark based framework to protect intellectual property of DNN. In: Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC 2019, pp. 126\u2013137 (2019). https:\/\/doi.org\/10.1145\/3359789.3359801","key":"3_CR19","DOI":"10.1145\/3359789.3359801"},{"issue":"7","key":"3_CR20","doi-asserted-by":"publisher","first-page":"1327","DOI":"10.1109\/TCAD.2020.3018403","volume":"40","author":"N Lin","year":"2021","unstructured":"Lin, N., Chen, X., Lu, H., Li, X.: Chaotic weights: a novel approach to protect intellectual property of deep neural networks. IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 40(7), 1327\u20131339 (2021). https:\/\/doi.org\/10.1109\/TCAD.2020.3018403","journal-title":"IEEE Trans. Comput. Aided Des. Integr. Circuits Syst."},{"unstructured":"Liu, Y.: Tools for mini-ImageNet Dataset (2020). https:\/\/github.com\/yaoyao-liu\/mini-imagenet-tools","key":"3_CR21"},{"issue":"2","key":"3_CR22","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1109\/TIFS.2010.2041812","volume":"5","author":"W Luo","year":"2010","unstructured":"Luo, W., Huang, F., Huang, J.: Edge adaptive image steganography based on LSB matching revisited. IEEE Trans. Inf. Forensics Secur. 5(2), 201\u2013214 (2010). https:\/\/doi.org\/10.1109\/TIFS.2010.2041812","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"doi-asserted-by":"crossref","unstructured":"Ong, D.S., Chan, C.S., Ng, K.W., Fan, L., Yang, Q.: Protecting intellectual property of generative adversarial networks from ambiguity attacks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 3630\u20133639 (2021)","key":"3_CR23","DOI":"10.1109\/CVPR46437.2021.00363"},{"issue":"1","key":"3_CR24","doi-asserted-by":"publisher","first-page":"2008613","DOI":"10.1080\/08839514.2021.2008613","volume":"36","author":"P Rathi","year":"2022","unstructured":"Rathi, P., Bhadauria, S., Rathi, S.: Watermarking of deep recurrent neural network using adversarial examples to protect intellectual property. Appl. Artif. Intell. 36(1), 2008613 (2022). https:\/\/doi.org\/10.1080\/08839514.2021.2008613","journal-title":"Appl. Artif. Intell."},{"key":"3_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"723","DOI":"10.1007\/978-3-030-11018-5_64","volume-title":"Computer Vision \u2013 ECCV 2018 Workshops","author":"A ur Rehman","year":"2019","unstructured":"ur Rehman, A., Rahim, R., Nadeem, S., ul\u00a0Hussain, S.: End-to-end trained CNN encoder-decoder networks for image steganography. In: Leal-Taix\u00e9, L., Roth, S. (eds.) ECCV 2018. LNCS, vol. 11132, pp. 723\u2013729. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-11018-5_64"},{"doi-asserted-by":"publisher","unstructured":"Rokhana, R., Herulambang, W., Indraswari, R.: Multi-class image classification based on MobileNetV2 for detecting the proper use of face mask. In: 2021 International Electronics Symposium (IES), pp. 636\u2013641 (2021). https:\/\/doi.org\/10.1109\/IES53407.2021.9594022","key":"3_CR26","DOI":"10.1109\/IES53407.2021.9594022"},{"unstructured":"Rouhani, B.D., Chen, H., Koushanfar, F.: DeepSigns: a generic watermarking framework for protecting the ownership of deep learning models. Cryptology ePrint Archive, Paper 2018\/311 (2018). https:\/\/eprint.iacr.org\/2018\/311","key":"3_CR27"},{"key":"3_CR28","doi-asserted-by":"publisher","first-page":"23409","DOI":"10.1109\/ACCESS.2021.3053998","volume":"9","author":"N Subramanian","year":"2021","unstructured":"Subramanian, N., Elharrouss, O., Al-Maadeed, S., Bouridane, A.: Image steganography: a review of the recent advances. IEEE Access 9, 23409\u201323423 (2021). https:\/\/doi.org\/10.1109\/ACCESS.2021.3053998","journal-title":"IEEE Access"},{"unstructured":"Tang, R., Du, M., Hu, X.: Deep serial number: computational watermarking for DNN intellectual property protection. CoRR abs\/2011.08960 (2020). https:\/\/arxiv.org\/abs\/2011.08960","key":"3_CR29"},{"unstructured":"Vinyals, O., Blundell, C., Lillicrap, T., Kavukcuoglu, K., Wierstra, D.: Matching networks for one shot learning. In: Proceedings of the 30th International Conference on Neural Information Processing Systems, NIPS 2016, pp. 3637\u20133645. Curran Associates Inc., Red Hook, NY, USA (2016). https:\/\/dl.acm.org\/doi\/10.5555\/3157382.3157504","key":"3_CR30"},{"issue":"7","key":"3_CR31","doi-asserted-by":"publisher","first-page":"2591","DOI":"10.1109\/TCSVT.2020.3030671","volume":"31","author":"H Wu","year":"2021","unstructured":"Wu, H., Liu, G., Yao, Y., Zhang, X.: Watermarking neural networks with watermarked images. IEEE Trans. Circuits Syst. Video Technol. 31(7), 2591\u20132601 (2021). https:\/\/doi.org\/10.1109\/TCSVT.2020.3030671","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"3_CR32","doi-asserted-by":"publisher","first-page":"47013","DOI":"10.1109\/ACCESS.2020.2978110","volume":"8","author":"Z Xiang","year":"2020","unstructured":"Xiang, Z., Sang, J., Zhang, Q., Cai, B., Xia, X., Wu, W.: A new convolutional neural network-based steganalysis method for content-adaptive image steganography in the spatial domain. IEEE Access 8, 47013\u201347020 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.2978110","journal-title":"IEEE Access"},{"doi-asserted-by":"publisher","unstructured":"Xu, G., Wu, H.Z., Shi, Y.Q.: Ensemble of CNNs for steganalysis: an empirical study. In: Proceedings of the 4th ACM Workshop on Information Hiding and Multimedia Security, IH &MMSec 2016, pp. 103\u2013107. Association for Computing Machinery, New York, NY, USA (2016). https:\/\/doi.org\/10.1145\/2909827.2930798","key":"3_CR33","DOI":"10.1145\/2909827.2930798"},{"issue":"5","key":"3_CR34","doi-asserted-by":"publisher","first-page":"708","DOI":"10.1109\/LSP.2016.2548421","volume":"23","author":"G Xu","year":"2016","unstructured":"Xu, G., Wu, H.Z., Shi, Y.Q.: Structural design of convolutional neural networks for steganalysis. IEEE Signal Process. Lett. 23(5), 708\u2013712 (2016). https:\/\/doi.org\/10.1109\/LSP.2016.2548421","journal-title":"IEEE Signal Process. Lett."},{"issue":"01","key":"3_CR35","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TAI.2021.3133824","volume":"1","author":"M Xue","year":"2022","unstructured":"Xue, M., Zhang, Y., Wang, J., Liu, W.: Intellectual property protection for deep learning models: taxonomy, methods, attacks, and evaluations. IEEE Trans. Artif. Intell. 1(01), 1\u20131 (2022). https:\/\/doi.org\/10.1109\/TAI.2021.3133824","journal-title":"IEEE Trans. Artif. Intell."},{"issue":"11","key":"3_CR36","doi-asserted-by":"publisher","first-page":"2545","DOI":"10.1109\/TIFS.2017.2710946","volume":"12","author":"J Ye","year":"2017","unstructured":"Ye, J., Ni, J., Yi, Y.: Deep learning hierarchical representations for image steganalysis. IEEE Trans. Inf. Forensics Secur. 12(11), 2545\u20132557 (2017). https:\/\/doi.org\/10.1109\/TIFS.2017.2710946","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"doi-asserted-by":"publisher","unstructured":"Zhang, J., et al.: Protecting intellectual property of deep neural networks with watermarking. In: Proceedings of the 2018 on Asia Conference on Computer and Communications Security, ASIACCS 2018, pp. 159\u2013172. Association for Computing Machinery, New York, NY, USA (2018). https:\/\/doi.org\/10.1145\/3196494.3196550","key":"3_CR37","DOI":"10.1145\/3196494.3196550"},{"key":"3_CR38","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TPAMI.2021.3064850","volume":"44","author":"J Zhang","year":"2021","unstructured":"Zhang, J., et al.: Deep model intellectual property protection via deep watermarking. IEEE Trans. Pattern Anal. Mach. Intell. 44, 1 (2021). https:\/\/doi.org\/10.1109\/TPAMI.2021.3064850","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"unstructured":"Zheng, L.: How to prove your model belongs to you: a blind-watermark based framework to protect intellectual property of DNN (2021). https:\/\/github.com\/zhenglisec\/Blind-Watermark-for-DNN","key":"3_CR39"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Digital Forensics and Cyber Crime"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-36574-4_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,15]],"date-time":"2023-07-15T13:02:16Z","timestamp":1689426136000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-36574-4_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031365737","9783031365744"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-36574-4_3","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"16 July 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICDF2C","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Digital Forensics and Cyber Crime","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Boston, MA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 November 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 November 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icdf2c2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confy plus","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"80","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}