{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T04:45:51Z","timestamp":1766378751997,"version":"3.48.0"},"publisher-location":"Singapore","reference-count":46,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789819665907"},{"type":"electronic","value":"9789819665914"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-6591-4_23","type":"book-chapter","created":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T08:38:52Z","timestamp":1750667932000},"page":"332-345","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["RAEDiff: Diffusion Models Enable Self-Generation and\u00a0Self-Recovery of\u00a0Reversible Adversarial Examples"],"prefix":"10.1007","author":[{"given":"Fan","family":"Xing","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3777-9479","authenticated-orcid":false,"given":"Xiaoyi","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongli","family":"Peng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhuo","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuefeng","family":"Fan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,6,24]]},"reference":[{"key":"23_CR1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s41651-020-00071-6","volume":"5","author":"D Banesh","year":"2021","unstructured":"Banesh, D., et al.: An image-based framework for ocean feature detection and analysis. J. Geovisualization Spat. Anal. 5, 1\u201321 (2021)","journal-title":"J. Geovisualization Spat. Anal."},{"key":"23_CR2","doi-asserted-by":"crossref","unstructured":"Chen, W., Song, D., Li, B.: TrojDiff: trojan attacks on diffusion models with diverse targets. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4035\u20134044 (2023)","DOI":"10.1109\/CVPR52729.2023.00393"},{"key":"23_CR3","doi-asserted-by":"crossref","unstructured":"Chou, S.Y., Chen, P.Y., Ho, T.Y.: How to backdoor diffusion models? In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4015\u20134024 (2023)","DOI":"10.1109\/CVPR52729.2023.00391"},{"key":"23_CR4","doi-asserted-by":"crossref","unstructured":"Dai, L., Mao, J., Xu, L., Fan, X., Zhou, X.: Balancing robustness and covertness in NLP model watermarking: A multi-task learning approach. In: 2023 IEEE Symposium on Computers and Communications, pp. 1376\u20131382. IEEE (2023)","DOI":"10.1109\/ISCC58397.2023.10218209"},{"key":"23_CR5","first-page":"8780","volume":"34","author":"P Dhariwal","year":"2021","unstructured":"Dhariwal, P., Nichol, A.: Diffusion models beat GANs on image synthesis. Adv. Neural. Inf. Process. Syst. 34, 8780\u20138794 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"issue":"5","key":"23_CR6","first-page":"953","volume":"59","author":"X Fan","year":"2022","unstructured":"Fan, X., Zhou, X., Zhu, B., Dong, J., Niu, J., Wang, H.: Survey of copyright protection schemes based on DNN model. J. Comput. Res. Dev. 59(5), 953\u2013977 (2022)","journal-title":"J. Comput. Res. Dev."},{"key":"23_CR7","doi-asserted-by":"crossref","unstructured":"Fu, D., Zhou, X., Xu, L., Hou, K., Chen, X.: Robust reversible watermarking by fractional order Zernike moments and Pseudo-Zernike moments. IEEE Trans. Circuits Syst. Video Tech. (2023)","DOI":"10.2139\/ssrn.4265342"},{"key":"23_CR8","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"23_CR9","unstructured":"Hertz, A., Mokady, R., Tenenbaum, J., Aberman, K., Pritch, Y., Cohen-Or, D.: Prompt-to-prompt image editing with cross attention control. arXiv preprint arXiv:2208.01626 (2022)"},{"key":"23_CR10","unstructured":"Heusel, M., Ramsauer, H., Unterthiner, T., Nessler, B., Hochreiter, S.: GANs trained by a two time-scale update rule converge to a local Nash equilibrium. Adv. Neural Inf. Process. Syst. 30 (2017)"},{"key":"23_CR11","first-page":"6840","volume":"33","author":"J Ho","year":"2020","unstructured":"Ho, J., Jain, A., Abbeel, P.: Denoising diffusion probabilistic models. Adv. Neural. Inf. Process. Syst. 33, 6840\u20136851 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"23_CR12","first-page":"23593","volume":"35","author":"B Kawar","year":"2022","unstructured":"Kawar, B., Elad, M., Ermon, S., Song, J.: Denoising diffusion restoration models. Adv. Neural. Inf. Process. Syst. 35, 23593\u201323606 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"23_CR13","unstructured":"Kingma, D.P., Salimans, T., Jozefowicz, R., Chen, X., Sutskever, I., Welling, M.: Improved variational inference with inverse autoregressive flow. Adv. Neural Inf. Process. Syst. 29 (2016)"},{"key":"23_CR14","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"key":"23_CR15","unstructured":"Kumar, S., Gupta, A., Walia, G.S.: Reversible data hiding: a contemporary survey of state-of-the-art, opportunities and challenges. Appl. Intell., 1\u201334 (2022)"},{"key":"23_CR16","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1016\/j.neunet.2022.01.009","volume":"148","author":"P Li","year":"2022","unstructured":"Li, P., Tu, S., Xu, L.: Deep rival penalized competitive learning for low-resolution face recognition. Neural Netw. 148, 183\u2013193 (2022)","journal-title":"Neural Netw."},{"key":"23_CR17","doi-asserted-by":"publisher","first-page":"109048","DOI":"10.1016\/j.patcog.2022.109048","volume":"134","author":"J Liu","year":"2023","unstructured":"Liu, J., Zhang, W., Fukuchi, K., Akimoto, Y., Sakuma, J.: Unauthorized AI cannot recognize me: reversible adversarial example. Pattern Recognit. 134, 109048 (2023)","journal-title":"Pattern Recognit."},{"key":"23_CR18","doi-asserted-by":"crossref","unstructured":"Liu, Z., Luo, P., Wang, X., Tang, X.: Deep learning face attributes in the wild. In: Proceedings of the IEEE International Conference on Computer Vision, pp. 3730\u20133738 (2015)","DOI":"10.1109\/ICCV.2015.425"},{"key":"23_CR19","unstructured":"Long, D., Jing, Z., Xuefeng, F., Xiaoyi, Z.: NLP neural network copyright protection based on black box watermark. Chin. J. Netw. Inf. Secur. 9(1) (2023)"},{"key":"23_CR20","doi-asserted-by":"crossref","unstructured":"Lugmayr, A., Danelljan, M., Romero, A., Yu, F., Timofte, R., Van\u00a0Gool, L.: Repaint: inpainting using denoising diffusion probabilistic models. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 11461\u201311471 (2022)","DOI":"10.1109\/CVPR52688.2022.01117"},{"key":"23_CR21","doi-asserted-by":"crossref","unstructured":"Mao, C., Chiquier, M., Wang, H., Yang, J., Vondrick, C.: Adversarial attacks are reversible with natural supervision. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 661\u2013671 (2021)","DOI":"10.1109\/ICCV48922.2021.00070"},{"key":"23_CR22","unstructured":"Meng, C., et al.: SDEdit: guided image synthesis and editing with stochastic differential equations. arXiv preprint arXiv:2108.01073 (2021)"},{"key":"23_CR23","unstructured":"Nair, N.G., Mei, K., Patel, V.M.: AT-DDPM: restoring faces degraded by atmospheric turbulence using denoising diffusion probabilistic models. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pp. 3434\u20133443 (2023)"},{"key":"23_CR24","unstructured":"Nguyen, A., Tran, A.: WANET\u2013imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369 (2021)"},{"key":"23_CR25","doi-asserted-by":"publisher","first-page":"108873","DOI":"10.1016\/j.patcog.2022.108873","volume":"131","author":"X Ning","year":"2022","unstructured":"Ning, X., Tian, W., Yu, Z., Li, W., Bai, X., Wang, Y.: HCFNN: high-order coverage function neural network for image classification. Pattern Recognit. 131, 108873 (2022)","journal-title":"Pattern Recognit."},{"key":"23_CR26","doi-asserted-by":"crossref","unstructured":"Rombach, R., Blattmann, A., Lorenz, D., Esser, P., Ommer, B.: High-resolution image synthesis with latent diffusion models. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 10684\u201310695 (2022)","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"23_CR27","doi-asserted-by":"crossref","unstructured":"Salem, A., Wen, R., Backes, M., Ma, S., Zhang, Y.: Dynamic backdoor attacks against machine learning models. In: 2022 IEEE 7th European Symposium on Security and Privacy, pp. 703\u2013718. IEEE (2022)","DOI":"10.1109\/EuroSP53844.2022.00049"},{"key":"23_CR28","unstructured":"Song, Y., Ermon, S.: Generative modeling by estimating gradients of the data distribution. Adv. Neural Inf. Process. Syst. 32 (2019)"},{"key":"23_CR29","unstructured":"Song, Y., Sohl-Dickstein, J., Kingma, D.P., Kumar, A., Ermon, S., Poole, B.: Score-based generative modeling through stochastic differential equations. arXiv preprint arXiv:2011.13456 (2020)"},{"key":"23_CR30","doi-asserted-by":"crossref","unstructured":"Wang, Y., Yu, J., Yu, R., Zhang, J.: Unlimited-size diffusion restoration. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 1160\u20131167 (2023)","DOI":"10.1109\/CVPRW59228.2023.00123"},{"key":"23_CR31","unstructured":"Wang, Y., Yu, J., Zhang, J.: Zero-shot image restoration using denoising diffusion null-space model. arXiv preprint arXiv:2212.00490 (2022)"},{"issue":"4","key":"23_CR32","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang, Z., Bovik, A.C., Sheikh, H.R., Simoncelli, E.P.: Image quality assessment: from error visibility to structural similarity. IEEE Trans. Image Process. 13(4), 600\u2013612 (2004)","journal-title":"IEEE Trans. Image Process."},{"key":"23_CR33","doi-asserted-by":"crossref","unstructured":"Wei, T., et al.: HairCLIP: design your hair by text and reference image. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 18072\u201318081 (2022)","DOI":"10.1109\/CVPR52688.2022.01754"},{"key":"23_CR34","doi-asserted-by":"crossref","unstructured":"Xia, B., et al.: DiffIR: efficient diffusion model for image restoration. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 13095\u201313105 (2023)","DOI":"10.1109\/ICCV51070.2023.01204"},{"key":"23_CR35","doi-asserted-by":"publisher","first-page":"109549","DOI":"10.1016\/j.patcog.2023.109549","volume":"140","author":"L Xiong","year":"2023","unstructured":"Xiong, L., Wu, Y., Yu, P., Zheng, Y.: A black-box reversible adversarial example for authorizable recognition to shared images. Pattern Recognit. 140, 109549 (2023)","journal-title":"Pattern Recognit."},{"issue":"6","key":"23_CR36","doi-asserted-by":"publisher","first-page":"7298","DOI":"10.1007\/s10489-022-03926-1","volume":"53","author":"M Xue","year":"2023","unstructured":"Xue, M., Wu, Y., Zhang, Y., Wang, J., Liu, W.: Dataset authorization control: protect the intellectual property of dataset via reversible feature space adversarial examples. Appl. Intell. 53(6), 7298\u20137309 (2023)","journal-title":"Appl. Intell."},{"key":"23_CR37","doi-asserted-by":"crossref","unstructured":"Yang, J., et al.: Unified contrastive learning in image-text-label space. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 19163\u201319173 (2022)","DOI":"10.1109\/CVPR52688.2022.01857"},{"key":"23_CR38","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.patrec.2022.12.018","volume":"166","author":"Z Yin","year":"2023","unstructured":"Yin, Z., Chen, L., Lyu, W., Luo, B.: Reversible attack based on adversarial perturbation and reversible data hiding in YUV colorspace. Pattern Recognit. Lett. 166, 1\u20137 (2023)","journal-title":"Pattern Recognit. Lett."},{"key":"23_CR39","unstructured":"Yin, Z., Wang, H., Chen, L., Wang, J., Zhang, W.: Reversible adversarial attack based on reversible image transformation. arXiv preprint arXiv:1911.02360 (2019)"},{"key":"23_CR40","doi-asserted-by":"crossref","unstructured":"Yu, J., Wang, Y., Zhao, C., Ghanem, B., Zhang, J.: Freedom: training-free energy-guided conditional diffusion model. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 23174\u201323184 (2023)","DOI":"10.1109\/ICCV51070.2023.02118"},{"key":"23_CR41","unstructured":"Yu, J., Zhang, X., Xu, Y., Zhang, J.: Cross: diffusion model makes controllable, robust and secure image steganography. Adv. Neural Inf. Process. Syst. 36 (2024)"},{"key":"23_CR42","doi-asserted-by":"crossref","unstructured":"Zhang, K., et al.: Benchmarking ultra-high-definition image super-resolution. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 14769\u201314778 (2021)","DOI":"10.1109\/ICCV48922.2021.01450"},{"key":"23_CR43","doi-asserted-by":"crossref","unstructured":"Zhang, R., Isola, P., Efros, A.A., Shechtman, E., Wang, O.: The unreasonable effectiveness of deep features as a perceptual metric. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 586\u2013595 (2018)","DOI":"10.1109\/CVPR.2018.00068"},{"issue":"8","key":"23_CR44","doi-asserted-by":"publisher","first-page":"1469","DOI":"10.1109\/TMM.2016.2569497","volume":"18","author":"W Zhang","year":"2016","unstructured":"Zhang, W., Wang, H., Hou, D., Yu, N.: Reversible data hiding in encrypted images by reversible image transformation. IEEE Trans. Multimed. 18(8), 1469\u20131479 (2016)","journal-title":"IEEE Trans. Multimed."},{"key":"23_CR45","first-page":"3609","volume":"35","author":"M Zhao","year":"2022","unstructured":"Zhao, M., Bao, F., Li, C., Zhu, J.: EGSDE: unpaired image-to-image translation via energy-guided stochastic differential equations. Adv. Neural. Inf. Process. Syst. 35, 3609\u20133623 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"23_CR46","doi-asserted-by":"crossref","unstructured":"Zhou, X., Hou, K., Zhuang, Y., Yin, Z., Han, W.: General pairwise modification framework for reversible data hiding in JPEG images. IEEE Trans. Cir. Syst. Video Tech. (2023)","DOI":"10.1109\/TCSVT.2023.3286393"}],"container-title":["Lecture Notes in Computer Science","Neural Information Processing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-6591-4_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T04:43:54Z","timestamp":1766378634000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-6591-4_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819665907","9789819665914"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-6591-4_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"24 June 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICONIP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Neural Information Processing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Auckland","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"New Zealand","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 December 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 December 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iconip2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/iconip2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}