{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T05:49:08Z","timestamp":1743140948759,"version":"3.40.3"},"publisher-location":"Cham","reference-count":17,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031377440"},{"type":"electronic","value":"9783031377457"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-37745-7_1","type":"book-chapter","created":{"date-parts":[[2023,7,28]],"date-time":"2023-07-28T21:01:48Z","timestamp":1690578108000},"page":"3-16","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Image Watermarking Backdoor Attacks in\u00a0CNN-Based Classification Tasks"],"prefix":"10.1007","author":[{"given":"Giovanbattista","family":"Abbate","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6461-1391","authenticated-orcid":false,"given":"Irene","family":"Amerini","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3471-1196","authenticated-orcid":false,"given":"Roberto","family":"Caldelli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,7,29]]},"reference":[{"key":"1_CR1","doi-asserted-by":"publisher","unstructured":"Barni, M., Kallas, K., Tondi, B.: A new backdoor attack in CNNs by training set corruption without label poisoning. In: 2019 IEEE International Conference on Image Processing (ICIP), pp. 101\u2013105 (2019). https:\/\/doi.org\/10.1109\/ICIP.2019.8802997","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"1_CR2","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.X.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv abs\/1712.05526 (2017)"},{"key":"1_CR3","doi-asserted-by":"publisher","unstructured":"Cox, I., Kilian, J., Leighton, F., Shamoon, T.: Secure spread spectrum watermarking for multimedia. IEEE Trans. Image Process. 6(12), 1673\u20131687 (1997). https:\/\/doi.org\/10.1109\/83.650120. https:\/\/ieeexplore.ieee.org\/document\/650120\/","DOI":"10.1109\/83.650120"},{"key":"1_CR4","doi-asserted-by":"publisher","unstructured":"Gao, Y., et al.: Backdoor attacks and countermeasures on deep learning: a comprehensive review (2020). https:\/\/doi.org\/10.48550\/ARXIV.2007.10760. https:\/\/arxiv.org\/abs\/2007.10760","DOI":"10.48550\/ARXIV.2007.10760"},{"issue":"7","key":"1_CR5","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1145\/3134599","volume":"61","author":"I Goodfellow","year":"2018","unstructured":"Goodfellow, I., McDaniel, P., Papernot, N.: Making machine learning robust against adversarial inputs. Commun. ACM 61(7), 56\u201366 (2018). https:\/\/doi.org\/10.1145\/3134599","journal-title":"Commun. ACM"},{"key":"1_CR6","doi-asserted-by":"publisher","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: Badnets: identifying vulnerabilities in the machine learning model supply chain (2017). https:\/\/doi.org\/10.48550\/ARXIV.1708.06733. https:\/\/arxiv.org\/abs\/1708.06733","DOI":"10.48550\/ARXIV.1708.06733"},{"key":"1_CR7","doi-asserted-by":"crossref","unstructured":"Guo, W., Tondi, B., Barni, M.: An overview of backdoor attacks against deep neural networks and possible defences. arXiv (2021). arXiv:2111.08429","DOI":"10.1109\/OJSP.2022.3190213"},{"key":"1_CR8","doi-asserted-by":"publisher","unstructured":"Hammoud, H.A.A.K., Ghanem, B.: Check your other door! creating backdoor attacks in the frequency domain (2021). https:\/\/doi.org\/10.48550\/ARXIV.2109.05507. https:\/\/arxiv.org\/abs\/2109.05507","DOI":"10.48550\/ARXIV.2109.05507"},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"Houben, S., Stallkamp, J., Salmen, J., Schlipsing, M., Igel, C.: Detection of traffic signs in real-world images: the German traffic sign detection benchmark. In: International Joint Conference on Neural Networks, no. 1288 (2013)","DOI":"10.1109\/IJCNN.2013.6706807"},{"key":"1_CR10","doi-asserted-by":"publisher","unstructured":"Kingma, D.P., Ba, J.: Adam: a method for stochastic optimization (2014). https:\/\/doi.org\/10.48550\/ARXIV.1412.6980. https:\/\/arxiv.org\/abs\/1412.6980","DOI":"10.48550\/ARXIV.1412.6980"},{"key":"1_CR11","unstructured":"LeCun, Y., Cortes, C.: MNIST handwritten digit database (2010). http:\/\/yann.lecun.com\/exdb\/mnist\/"},{"key":"1_CR12","unstructured":"Liu, Y., Ma, X., Bailey, J., Lu, F.: Reflection backdoor: a natural backdoor attack on deep neural networks. arXiv:2007.02343 (2020). http:\/\/arxiv.org\/abs\/2007.02343. arXiv: 2007.02343"},{"key":"1_CR13","unstructured":"van der Maaten, L., Hinton, G.: Visualizing data using t-SNE. J. Mach. Learn. Res. 9(86), 2579\u20132605 (2008). http:\/\/jmlr.org\/papers\/v9\/vandermaaten08a.html"},{"key":"1_CR14","doi-asserted-by":"publisher","unstructured":"Mu\u00f1oz-Gonz\u00e1lez, L., et al.: Towards poisoning of deep learning algorithms with back-gradient optimization. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, pp. 27\u201338. ACM (2017). https:\/\/doi.org\/10.1145\/3128572.3140451. https:\/\/dl.acm.org\/doi\/10.1145\/3128572.3140451","DOI":"10.1145\/3128572.3140451"},{"key":"1_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/10719724_12","volume-title":"Information Hiding","author":"A De Rosa","year":"2000","unstructured":"De Rosa, A., Barni, M., Bartolini, F., Cappellini, V., Piva, A.: Optimum decoding of non-additive full frame DFT watermarks. In: Pfitzmann, A. (ed.) IH 1999. LNCS, vol. 1768, pp. 159\u2013171. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/10719724_12"},{"key":"1_CR16","doi-asserted-by":"publisher","unstructured":"Wang, T., Yao, Y., Xu, F., An, S., Tong, H., Wang, T.: Backdoor attack through frequency domain (2021). https:\/\/doi.org\/10.48550\/ARXIV.2111.10991. https:\/\/arxiv.org\/abs\/2111.10991","DOI":"10.48550\/ARXIV.2111.10991"},{"key":"1_CR17","doi-asserted-by":"publisher","unstructured":"Xiao, H., Eckert, C.: Adversarial label flips attack on support vector machines. In: ECAI 2012: Proceedings of the 20th European Conference on Artificial Intelligence, pp. 870\u2013875 (2012). https:\/\/doi.org\/10.3233\/978-1-61499-098-7-870","DOI":"10.3233\/978-1-61499-098-7-870"}],"container-title":["Lecture Notes in Computer Science","Pattern Recognition, Computer Vision, and Image Processing. ICPR 2022 International Workshops and Challenges"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-37745-7_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,28]],"date-time":"2023-07-28T21:05:17Z","timestamp":1690578317000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-37745-7_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031377440","9783031377457"],"references-count":17,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-37745-7_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"29 July 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICPR","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Pattern Recognition","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Montr\u00e9al, QC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icpr2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/iapr.org\/icpr2022","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}