{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T00:47:24Z","timestamp":1760316444735,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":53,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032078834","type":"print"},{"value":"9783032078841","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T00:00:00Z","timestamp":1760313600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T00:00:00Z","timestamp":1760313600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-07884-1_18","type":"book-chapter","created":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T16:23:03Z","timestamp":1760286183000},"page":"346-365","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Trigger-Based Fragile Model Watermarking for\u00a0Image Transformation Networks"],"prefix":"10.1007","author":[{"given":"Preston K.","family":"Robinette","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thuy Dung","family":"Nguyen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Samuel","family":"Sasaki","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Taylor T.","family":"Johnson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,13]]},"reference":[{"key":"18_CR1","unstructured":"Adi, Y., Baum, C., Cisse, M., Pinkas, B., Keshet, J.: Turning your weakness into a strength: watermarking deep neural networks by backdooring. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 1615\u20131631 (2018)"},{"key":"18_CR2","unstructured":"Bansal, A., et al.: Certified neural network watermarks with randomized smoothing. In: International Conference on Machine Learning, pp. 1450\u20131465. PMLR (2022)"},{"issue":"1","key":"18_CR3","doi-asserted-by":"publisher","first-page":"1057","DOI":"10.1007\/s12652-020-02135-3","volume":"12","author":"S Bhalerao","year":"2021","unstructured":"Bhalerao, S., Ansari, I.A., Kumar, A.: A secure image watermarking for tamper detection and localization. J. Ambient. Intell. Humaniz. Comput. 12(1), 1057\u20131068 (2021)","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"18_CR4","doi-asserted-by":"crossref","unstructured":"Chen, Y., Kumara, E.K., Sivakumar, V.: Invesitigation of finance industry on risk awareness model and digital economic growth. Ann. Oper. Res., 1\u201322 (2021)","DOI":"10.1007\/s10479-021-04287-7"},{"issue":"3","key":"18_CR5","doi-asserted-by":"publisher","first-page":"414","DOI":"10.1117\/1.1494075","volume":"11","author":"I Cox","year":"2002","unstructured":"Cox, I., Miller, M., Bloom, J., Honsinger, C.: Digital watermarking. J. Electron. Imaging 11(3), 414 (2002)","journal-title":"J. Electron. Imaging"},{"issue":"8035","key":"18_CR6","doi-asserted-by":"publisher","first-page":"818","DOI":"10.1038\/s41586-024-08025-4","volume":"634","author":"S Dathathri","year":"2024","unstructured":"Dathathri, S., et al.: Scalable watermarking for identifying large language model outputs. Nature 634(8035), 818\u2013823 (2024)","journal-title":"Nature"},{"key":"18_CR7","unstructured":"Doan, K.D., Lao, Y., Li, P.: Marksman backdoor: backdoor attacks with arbitrary target class. In: Advances in Neural Information Processing Systems, vol. 35, pp. 38260\u201338273 (2022)"},{"key":"18_CR8","doi-asserted-by":"crossref","unstructured":"Fridrich, J.: Image watermarking for tamper detection. In: Proceedings 1998 International Conference on Image Processing. ICIP98 (Cat. No. 98CB36269), vol.\u00a02, pp. 404\u2013408. IEEE (1998)","DOI":"10.1109\/ICIP.1998.723401"},{"issue":"7","key":"18_CR9","doi-asserted-by":"publisher","first-page":"1079","DOI":"10.1109\/5.771066","volume":"87","author":"F Hartung","year":"1999","unstructured":"Hartung, F., Kutter, M.: Multimedia watermarking techniques. Proc. IEEE 87(7), 1079\u20131107 (1999)","journal-title":"Proc. IEEE"},{"key":"18_CR10","unstructured":"Ho, J., Jain, A., Abbeel, P.: Denoising diffusion probabilistic models. In: Advances in Neural Information Processing Systems, vol. 33, pp. 6840\u20136851 (2020)"},{"key":"18_CR11","unstructured":"Hong, S., Carlini, N., Kurakin, A.: Handcrafted backdoors in deep neural networks. In: Advances in Neural Information Processing Systems, vol. 35, pp. 8068\u20138080 (2022)"},{"key":"18_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109844","volume":"144","author":"G Hua","year":"2023","unstructured":"Hua, G., Teoh, A.B.J.: Deep fidelity in DNN watermarking: a study of backdoor watermarking for classification models. Pattern Recogn. 144, 109844 (2023)","journal-title":"Pattern Recogn."},{"key":"18_CR13","unstructured":"Jaeger, P.F., et al.: Retina U-Net: embarrassingly simple exploitation of segmentation supervision for medical object detection. In: Machine Learning for Health Workshop, pp. 171\u2013183. PMLR (2020)"},{"issue":"8","key":"18_CR14","doi-asserted-by":"publisher","DOI":"10.2196\/38440","volume":"10","author":"B Joe","year":"2022","unstructured":"Joe, B., Park, Y., Hamm, J., Shin, I., Lee, J., et al.: Exploiting missing value patterns for a backdoor attack on machine learning models of electronic health records: development and validation study. JMIR Med. Inform. 10(8), e38440 (2022)","journal-title":"JMIR Med. Inform."},{"key":"18_CR15","doi-asserted-by":"publisher","first-page":"3225","DOI":"10.1007\/s11277-021-08177-w","volume":"118","author":"P Kadian","year":"2021","unstructured":"Kadian, P., Arora, S.M., Arora, N.: Robust digital watermarking techniques for copyright protection of digital data: a survey. Wireless Pers. Commun. 118, 3225\u20133249 (2021)","journal-title":"Wireless Pers. Commun."},{"key":"18_CR16","unstructured":"Kim, B., Lee, S., Lee, S., Son, S., Hwang, S.J.: Margin-based neural network watermarking. In: International Conference on Machine Learning, pp. 16696\u201316711. PMLR (2023)"},{"key":"18_CR17","unstructured":"Kirchenbauer, J., Geiping, J., Wen, Y., Katz, J., Miers, I., Goldstein, T.: A watermark for large language models. arXiv preprint arXiv:2301.10226 (2023)"},{"issue":"1","key":"18_CR18","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/TNNLS.2022.3182979","volume":"35","author":"Y Li","year":"2022","unstructured":"Li, Y., Jiang, Y., Li, Z., Xia, S.T.: Backdoor learning: a survey. IEEE Trans. Neural Netw. Learn. Syst. 35(1), 5\u201322 (2022)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"18_CR19","doi-asserted-by":"crossref","unstructured":"Li, Y., Li, Y., Wu, B., Li, L., He, R., Lyu, S.: Invisible backdoor attack with sample-specific triggers. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 16463\u201316472 (2021)","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"18_CR20","unstructured":"Lin, E.T., Delp, E.J.: A review of fragile image watermarks. In: Proceedings of the Multimedia and Security Workshop at ACM Multimedia, vol.\u00a099, pp. 35\u201339 (1999)"},{"issue":"12","key":"18_CR21","doi-asserted-by":"publisher","first-page":"2519","DOI":"10.1016\/j.patcog.2005.02.007","volume":"38","author":"PL Lin","year":"2005","unstructured":"Lin, P.L., Hsieh, C.K., Huang, P.W.: A hierarchical digital watermarking method for image tamper detection and recovery. Pattern Recogn. 38(12), 2519\u20132529 (2005)","journal-title":"Pattern Recogn."},{"key":"18_CR22","unstructured":"Liu, H., Weng, Z., Zhu, Y.: Watermarking deep neural networks with greedy residuals. In: ICML, pp. 6978\u20136988 (2021)"},{"key":"18_CR23","doi-asserted-by":"publisher","unstructured":"Liu, X., et al.: Watermark vaccine: adversarial attacks to prevent watermark removal. In: Avidan, S., Brostow, G., Ciss\u00e9, M., Farinella, G.M., Hassner, T. (eds.) ECCV 2022. LNCS, vol. 13674, pp. 1\u201317. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-19781-9_1","DOI":"10.1007\/978-3-031-19781-9_1"},{"key":"18_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1007\/978-3-030-58607-2_11","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Y Liu","year":"2020","unstructured":"Liu, Y., Ma, X., Bailey, J., Lu, F.: Reflection backdoor: a natural backdoor attack on deep neural networks. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12355, pp. 182\u2013199. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58607-2_11"},{"key":"18_CR25","doi-asserted-by":"crossref","unstructured":"Liu, Y., et al.: A survey on neural trojans. In: 2020 21st International Symposium on Quality Electronic Design (ISQED), pp. 33\u201339. IEEE (2020)","DOI":"10.1109\/ISQED48828.2020.9137011"},{"key":"18_CR26","unstructured":"Mohanty, S.P.: Digital watermarking: a tutorial review (1999). http:\/\/www.csee.usf.edu\/~smohanty\/research\/Reports\/WMSurvey1999Mohanty.pdf"},{"key":"18_CR27","doi-asserted-by":"crossref","unstructured":"Ohbuchi, R., Ueda, H., Endoh, S.: Robust watermarking of vector digital maps. In: Proceedings. IEEE International Conference on Multimedia and Expo, vol.\u00a01, pp. 577\u2013580. IEEE (2002)","DOI":"10.1109\/ICME.2002.1035847"},{"issue":"4","key":"18_CR28","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1109\/79.939835","volume":"18","author":"C Podilchuk","year":"2001","unstructured":"Podilchuk, C., Delp, E.: Digital watermarking: algorithms and applications. IEEE Signal Process. Mag. 18(4), 33\u201346 (2001). https:\/\/doi.org\/10.1109\/79.939835","journal-title":"IEEE Signal Process. Mag."},{"key":"18_CR29","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103102","volume":"127","author":"T Qiao","year":"2023","unstructured":"Qiao, T., et al.: A novel model watermarking for protecting generative adversarial network. Comput. Secur. 127, 103102 (2023)","journal-title":"Comput. Secur."},{"issue":"5","key":"18_CR30","doi-asserted-by":"publisher","first-page":"1852","DOI":"10.1109\/TNNLS.2020.2991378","volume":"32","author":"Y Quan","year":"2020","unstructured":"Quan, Y., Teng, H., Chen, Y., Ji, H.: Watermarking deep neural networks in image processing. IEEE Trans. Neural Netw. Learn. Syst. 32(5), 1852\u20131865 (2020)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"18_CR31","unstructured":"Ren, J., Zhou, Y., Jin, J., Lyu, L., Yan, D.: Dimension-independent certified neural network watermarks via mollifier smoothing. In: International Conference on Machine Learning, pp. 28976\u201329008. PMLR (2023)"},{"key":"18_CR32","doi-asserted-by":"crossref","unstructured":"Rezaei, A., Akbari, M., Alvar, S.R., Fatemi, A., Zhang, Y.: LaWa: using latent space for in-generation image watermarking. In: Leonardis, A., Ricci, E., Roth, S., Russakovsky, O., Sattler, T., Varol, G. (eds.) ECCV 2024. LNCS, vol. 15147, pp. 118\u2013136. Springer, Cham (2024)","DOI":"10.1007\/978-3-031-73024-5_8"},{"key":"18_CR33","doi-asserted-by":"publisher","unstructured":"Ronneberger, O., Fischer, P., Brox, T.: U-Net: convolutional networks for biomedical image segmentation. In: Navab, N., Hornegger, J., Wells, W., Frangi, A. (eds.) MICCAI 2015, Part III. LNCS, vol. 9351, pp. 234\u2013241. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-24574-4_28","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"18_CR34","unstructured":"Rouhani, B.D., Chen, H., Koushanfar, F.: DeepSigns: a generic watermarking framework for IP protection of deep learning models. arXiv preprint arXiv:1804.00750 (2018)"},{"key":"18_CR35","doi-asserted-by":"crossref","unstructured":"Saha, A., Subramanya, A., Pirsiavash, H.: Hidden trigger backdoor attacks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a034, pp. 11957\u201311965 (2020)","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"18_CR36","unstructured":"Shafahi, A., et al.: Poison frogs! Targeted clean-label poisoning attacks on neural networks. In: Advances in Neural Information Processing Systems, vol. 31 (2018)"},{"key":"18_CR37","doi-asserted-by":"crossref","unstructured":"Shafieinejad, M., Lukas, N., Wang, J., Li, X., Kerschbaum, F.: On the robustness of backdoor-based watermarking in deep neural networks. In: Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security, pp. 177\u2013188 (2021)","DOI":"10.1145\/3437880.3460401"},{"key":"18_CR38","unstructured":"Souri, H., Fowl, L., Chellappa, R., Goldblum, M., Goldstein, T.: Sleeper agent: scalable hidden trigger backdoors for neural networks trained from scratch. In: Advances in Neural Information Processing Systems, vol. 35, pp. 19165\u201319178 (2022)"},{"key":"18_CR39","doi-asserted-by":"crossref","unstructured":"Uchida, Y., Nagai, Y., Sakazawa, S., Satoh, S.: Embedding watermarks into deep neural networks. In: Proceedings of the 2017 ACM on International Conference on Multimedia Retrieval, pp. 269\u2013277 (2017)","DOI":"10.1145\/3078971.3078974"},{"key":"18_CR40","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1016\/j.neucom.2022.02.083","volume":"488","author":"W Wan","year":"2022","unstructured":"Wan, W., Wang, J., Zhang, Y., Li, J., Yu, H., Sun, J.: A comprehensive survey on robust image watermarking. Neurocomputing 488, 226\u2013247 (2022)","journal-title":"Neurocomputing"},{"issue":"4","key":"18_CR41","doi-asserted-by":"publisher","first-page":"22-1","DOI":"10.2352\/ISSN.2470-1173.2020.4.MWSF-022","volume":"2020","author":"J Wang","year":"2020","unstructured":"Wang, J., Wu, H., Zhang, X., Yao, Y.: Watermarking in deep neural networks via error back-propagation. Electron. Imaging 2020(4), 22-1\u201322-9 (2020)","journal-title":"Electron. Imaging"},{"key":"18_CR42","doi-asserted-by":"crossref","unstructured":"Wang, T., Kerschbaum, F.: Attacks on digital watermarks for deep neural networks. In: ICASSP 2019-2019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 2622\u20132626. IEEE (2019)","DOI":"10.1109\/ICASSP.2019.8682202"},{"key":"18_CR43","doi-asserted-by":"publisher","unstructured":"Wang, T., Yao, Y., Xu, F., An, S., Tong, H., Wang, T.: An invisible black-box backdoor attack through frequency domain. In: Avidan, S., Brostow, G., Ciss\u00e9, M., Farinella, G.M., Hassner, T. (eds.) ECCV 2022. LNCS, vol. 13673, pp. 396\u2013413. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-19778-9_23","DOI":"10.1007\/978-3-031-19778-9_23"},{"key":"18_CR44","doi-asserted-by":"publisher","unstructured":"Wang, Y., Sarkar, E., Jabari, S.E., Maniatakos, M.: On the vulnerability of deep reinforcement learning to backdoor attacks in autonomous vehicles. In: Pasricha, S., Shafique, M. (eds.) Embedded Machine Learning for Cyber-Physical, IoT, and Edge Computing: Use Cases and Emerging Challenges, pp. 315\u2013341. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-40677-5_13","DOI":"10.1007\/978-3-031-40677-5_13"},{"key":"18_CR45","unstructured":"Wen, Y., Kirchenbauer, J., Geiping, J., Goldstein, T.: Tree-ring watermarks: fingerprints for diffusion images that are invisible and robust. arXiv preprint arXiv:2305.20030 (2023)"},{"key":"18_CR46","doi-asserted-by":"crossref","unstructured":"Wolfgang, R.B., Delp\u00a0III, E.J.: Fragile watermarking using the VW2D watermark. In: Security and Watermarking of Multimedia Contents, vol.\u00a03657, pp. 204\u2013213. SPIE (1999)","DOI":"10.1117\/12.344670"},{"key":"18_CR47","doi-asserted-by":"crossref","unstructured":"Yin, H., Yin, Z., Gao, Z., Su, H., Zhang, X., Luo, B.: FTG: score-based black-box watermarking by fragile trigger generation for deep model integrity verification. J. Inf. Intell. (2023)","DOI":"10.1016\/j.jiixd.2023.10.006"},{"key":"18_CR48","doi-asserted-by":"crossref","unstructured":"Yin, Z., Yin, H., Zhang, X.: Neural network fragile watermarking with no model performance degradation. In: 2022 IEEE International Conference on Image Processing (ICIP), pp. 3958\u20133962. IEEE (2022)","DOI":"10.1109\/ICIP46576.2022.9897413"},{"key":"18_CR49","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121315","volume":"236","author":"Z Yuan","year":"2024","unstructured":"Yuan, Z., Zhang, X., Wang, Z., Yin, Z.: Semi-fragile neural network watermarking for content authentication and tampering localization. Expert Syst. Appl. 236, 121315 (2024)","journal-title":"Expert Syst. Appl."},{"key":"18_CR50","doi-asserted-by":"crossref","unstructured":"Zhang, J., et al.: Model watermarking for image processing networks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a034, pp. 12805\u201312812 (2020)","DOI":"10.1609\/aaai.v34i07.6976"},{"issue":"8","key":"18_CR51","first-page":"4005","volume":"44","author":"J Zhang","year":"2021","unstructured":"Zhang, J., et al.: Deep model intellectual property protection via deep watermarking. IEEE Trans. Pattern Anal. Mach. Intell. 44(8), 4005\u20134020 (2021)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"18_CR52","unstructured":"Zhao, X., Wang, Y.X., Li, L.: Protecting language generation models via invisible watermarking. arXiv preprint arXiv:2302.03162 (2023)"},{"key":"18_CR53","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/978-3-030-82136-4_23","volume-title":"Knowledge Science, Engineering and Management","author":"R Zhu","year":"2021","unstructured":"Zhu, R., Wei, P., Li, S., Yin, Z., Zhang, X., Qian, Z.: Fragile neural network watermarking with trigger image set. In: Qiu, H., Zhang, C., Fei, Z., Qiu, M., Kung, S.-Y. (eds.) KSEM 2021. LNCS (LNAI), vol. 12815, pp. 280\u2013293. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-82136-4_23"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-07884-1_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T16:23:14Z","timestamp":1760286194000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-07884-1_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"ISBN":["9783032078834","9783032078841"],"references-count":53,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-07884-1_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"13 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}