{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:14:44Z","timestamp":1777655684049,"version":"3.51.4"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031434266","type":"print"},{"value":"9783031434273","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-43427-3_10","type":"book-chapter","created":{"date-parts":[[2023,9,16]],"date-time":"2023-09-16T21:01:41Z","timestamp":1694898101000},"page":"157-173","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Deep Serial Number: Computational Watermark for\u00a0DNN Intellectual Property Protection"],"prefix":"10.1007","author":[{"given":"Ruixiang","family":"Tang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mengnan","family":"Du","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xia","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,9,17]]},"reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"Boenisch, F.: A survey on model watermarking neural networks. arXiv preprint arXiv:2009.12153 (2020)","DOI":"10.3389\/fdata.2021.729663"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Chen, H., Fu, C., Zhao, J., Koushanfar, F.: Deepinspect: a black-box trojan detection and mitigation framework for deep neural networks. In: IJCAI, pp. 4658\u20134664 (2019)","DOI":"10.24963\/ijcai.2019\/647"},{"key":"10_CR3","unstructured":"Chen, X., et al.: Refit: a unified watermark removal framework for deep learning systems with limited data. arXiv preprint arXiv:1911.07205 (2019)"},{"key":"10_CR4","unstructured":"Fan, L., Ng, K.W., Chan, C.S.: Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks. In: NIPS, pp. 4714\u20134723 (2019)"},{"key":"10_CR5","unstructured":"Furlanello, T., Lipton, Z.C., Tschannen, M., Itti, L., Anandkumar, A.: Born again neural networks. arXiv preprint arXiv:1805.04770 (2018)"},{"key":"10_CR6","unstructured":"Ganin, Y., Lempitsky, V.: Unsupervised domain adaptation by backpropagation. In: ICML, pp. 1180\u20131189. PMLR (2015)"},{"key":"10_CR7","unstructured":"Gou, J., Yu, B., Maybank, S.J., Tao, D.: Knowledge distillation: a survey. arXiv preprint arXiv:2006.05525 (2020)"},{"key":"10_CR8","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: Badnets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019)","journal-title":"IEEE Access"},{"key":"10_CR9","unstructured":"Han, S., Mao, H., Dally, W.J.: Deep compression: compressing deep neural networks with pruning, trained quantization and huffman coding. arXiv preprint arXiv:1510.00149 (2015)"},{"key":"10_CR10","unstructured":"Hinton, G., Vinyals, O., Dean, J.: Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531 (2015)"},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Huang, X., Belongie, S.: Arbitrary style transfer in real-time with adaptive instance normalization. In: ICCV, pp. 1501\u20131510 (2017)","DOI":"10.1109\/ICCV.2017.167"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Kapusta, K., Thouvenot, V., Bettan, O., Beguinet, H., Senet, H.: A protocol for secure verification of watermarks embedded into machine learning models. In: Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security, pp. 171\u2013176 (2021)","DOI":"10.1145\/3437880.3460409"},{"key":"10_CR13","unstructured":"Kirchenbauer, J., Geiping, J., Wen, Y., Katz, J., Miers, I., Goldstein, T.: A watermark for large language models. arXiv preprint arXiv:2301.10226 (2023)"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Kumar, N., Berg, A.C., Belhumeur, P.N., Nayar, S.K.: Attribute and simile classifiers for face verification. In: ICCV, pp. 365\u2013372. IEEE (2009)","DOI":"10.1109\/ICCV.2009.5459250"},{"issue":"11","key":"10_CR15","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun, Y., Bottou, L., Bengio, Y., Haffner, P.: Gradient-based learning applied to document recognition. Proc. IEEE 86(11), 2278\u20132324 (1998)","journal-title":"Proc. IEEE"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"Li, G., Li, S., Qian, Z., Zhang, X.: Encryption resistant deep neural network watermarking. In: ICASSP 2022\u20132022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 3064\u20133068. IEEE (2022)","DOI":"10.1109\/ICASSP43922.2022.9746461"},{"key":"10_CR17","unstructured":"Li, H., Wenger, E., Zhao, B.Y., Zheng, H.: Piracy resistant watermarks for deep neural networks. arXiv preprint arXiv:1910.01226 (2019)"},{"key":"10_CR18","unstructured":"Li, Y., Bai, Y., Jiang, Y., Yang, Y., Xia, S.T., Li, B.: Untargeted backdoor watermark: towards harmless and stealthy dataset copyright protection. In: Advances in Neural Information Processing Systems (2022)"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Li, Y., Jiang, Y., Li, Z., Xia, S.T.: Backdoor learning: a survey. IEEE Trans. Neural Netw. Learn. Syst. (2022)","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"10_CR20","doi-asserted-by":"publisher","first-page":"2318","DOI":"10.1109\/TIFS.2023.3265535","volume":"18","author":"Y Li","year":"2023","unstructured":"Li, Y., Zhu, M., Yang, X., Jiang, Y., Wei, T., Xia, S.T.: Black-box dataset ownership verification via backdoor watermarking. IEEE Trans. Inf. Forensics Secur. 18, 2318\u20132332 (2023)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10_CR21","doi-asserted-by":"crossref","unstructured":"Lounici, S., Njeh, M., Ermis, O., \u00d6nen, M., Trabelsi, S.: Yes we can: watermarking machine learning models beyond classification. In: 2021 IEEE 34th Computer Security Foundations Symposium (CSF), pp. 1\u201314. IEEE (2021)","DOI":"10.1109\/CSF51468.2021.00044"},{"key":"10_CR22","doi-asserted-by":"crossref","unstructured":"Oliynyk, D., Mayer, R., Rauber, A.: I know what you trained last summer: a survey on stealing machine learning models and defences. arXiv preprint arXiv:2206.08451 (2022)","DOI":"10.1145\/3595292"},{"key":"10_CR23","doi-asserted-by":"crossref","unstructured":"Parkhi, O.M., Vedaldi, A., Zisserman, A.: Deep face recognition. In: British Machine Vision Association (2015)","DOI":"10.5244\/C.29.41"},{"issue":"2","key":"10_CR24","doi-asserted-by":"publisher","first-page":"180","DOI":"10.1049\/cit2.12029","volume":"6","author":"F Regazzoni","year":"2021","unstructured":"Regazzoni, F., Palmieri, P., Smailbegovic, F., Cammarota, R., Polian, I.: Protecting artificial intelligence IPS: a survey of watermarking and fingerprinting for machine learning. CAAI Trans. Intell. Technol. 6(2), 180\u2013191 (2021)","journal-title":"CAAI Trans. Intell. Technol."},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"Sanyal, S., Addepalli, S., Babu, R.V.: Towards data-free model stealing in a hard label setting. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 15284\u201315293 (2022)","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"10_CR26","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1016\/j.neunet.2012.02.016","volume":"32","author":"J Stallkamp","year":"2012","unstructured":"Stallkamp, J., Schlipsing, M., Salmen, J., Igel, C.: Man vs. computer: benchmarking machine learning algorithms for traffic sign recognition. Neural Networks 32, 323\u2013332 (2012)","journal-title":"Neural Networks"},{"key":"10_CR27","unstructured":"Tang, R., Chuang, Y.N., Hu, X.: The science of detecting LLM-generated texts. arXiv preprint arXiv:2303.07205 (2023)"},{"key":"10_CR28","doi-asserted-by":"crossref","unstructured":"Tang, R., Du, M., Liu, N., Yang, F., Hu, X.: An embarrassingly simple approach for trojan attack in deep neural networks. In: KDD, pp. 218\u2013228 (2020)","DOI":"10.1145\/3394486.3403064"},{"key":"10_CR29","doi-asserted-by":"crossref","unstructured":"Tang, R., Feng, Q., Liu, N., Yang, F., Hu, X.: Did you train on my dataset? Towards public dataset protection with clean-label backdoor watermarking. arXiv preprint arXiv:2303.11470 (2023)","DOI":"10.1145\/3606274.3606279"},{"key":"10_CR30","doi-asserted-by":"crossref","unstructured":"Uchida, Y., Nagai, Y., Sakazawa, S., Satoh, S.: Embedding watermarks into deep neural networks. In: MM, pp. 269\u2013277 (2017)","DOI":"10.1145\/3078971.3078974"},{"key":"10_CR31","unstructured":"Vincent, J.: Meta\u2019s powerful AI language model has leaked online: what happens now? The Verge (2023). https:\/\/www.theverge.com\/2023\/3\/8\/23629362\/meta-ai-language-model-llama-leak-online-misuse"},{"key":"10_CR32","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 707\u2013723. IEEE (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"10_CR33","doi-asserted-by":"crossref","unstructured":"Wang, L., Song, Y., Xia, D.: Deep neural network watermarking based on a reversible image hiding network. Pattern Analysis and Applications, pp. 1\u201314 (2023)","DOI":"10.1007\/s10044-023-01140-4"},{"key":"10_CR34","doi-asserted-by":"crossref","unstructured":"Wang, R., et al.: Rethinking the vulnerability of DNN watermarking: are watermarks robust against naturalness-aware perturbations? In: Proceedings of the 30th ACM International Conference on Multimedia, pp. 1808\u20131818 (2022)","DOI":"10.1145\/3503161.3548390"},{"key":"10_CR35","unstructured":"Yang, J., et al.: Harnessing the power of LLMS in practice: a survey on ChatGPT and beyond. arXiv preprint arXiv:2304.13712 (2023)"},{"key":"10_CR36","unstructured":"Yang, Z., Dang, H., Chang, E.C.: Effectiveness of distillation attack and countermeasure on neural network watermarking. arXiv preprint arXiv:1906.06046 (2019)"}],"container-title":["Lecture Notes in Computer Science","Machine Learning and Knowledge Discovery in Databases: Applied Data Science and Demo Track"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-43427-3_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,16]],"date-time":"2023-09-16T21:02:50Z","timestamp":1694898170000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-43427-3_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031434266","9783031434273"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-43427-3_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"17 September 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Turin","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2023.ecmlpkdd.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"CMT","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"829","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"196","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"24% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.63","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4.5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Applied Data Science Track: 239 submissions, 58 accepted papers; Demo Track: 31 submissions, 16 accepted papers.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}