{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T17:04:54Z","timestamp":1783098294249,"version":"3.54.6"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T00:00:00Z","timestamp":1732752000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T00:00:00Z","timestamp":1732752000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"scientific and technological innovation of Fujian agriculture and Forestry University","award":["KFb22091XA"],"award-info":[{"award-number":["KFb22091XA"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61972093"],"award-info":[{"award-number":["61972093"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2025,1]]},"DOI":"10.1007\/s10489-024-05917-w","type":"journal-article","created":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T05:44:21Z","timestamp":1732772661000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["ISWP: Novel high-fidelity adversarial examples generated by incorporating invisible and secure watermark perturbations"],"prefix":"10.1007","volume":"55","author":[{"given":"Jinchao","family":"Liang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lu","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ze","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3427-9255","authenticated-orcid":false,"given":"Xiaolong","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,11,28]]},"reference":[{"key":"5917_CR1","doi-asserted-by":"publisher","first-page":"4114","DOI":"10.1109\/TIFS.2024.3372811","volume":"19","author":"Y Tang","year":"2024","unstructured":"Tang Y, Wang C, Xiang S, Cheung YM (2024) Reversible watermarking scheme using attack-simulation-based adaptive normalization and embedding. IEEE Trans Inf Forensics Secur 19:4114\u20134129. https:\/\/doi.org\/10.1109\/TIFS.2024.3372811","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"5917_CR2","doi-asserted-by":"crossref","unstructured":"Taj T, Sarkar M (2023) A survey on embedding iris biometric watermarking for user authentication. Cloud Comput Data Sci: 203\u2013211","DOI":"10.37256\/ccds.4220233051"},{"key":"5917_CR3","first-page":"1","volume":"99","author":"S Das","year":"2022","unstructured":"Das S, Namasudra S (2022) A lightweight and anonymous mutual authentication scheme for medical big data in distributed smart healthcare systems. IEEE\/ACM Trans Comput Biol Bioinf 99:1\u201312","journal-title":"IEEE\/ACM Trans Comput Biol Bioinf"},{"issue":"9","key":"5917_CR4","doi-asserted-by":"publisher","first-page":"9992","DOI":"10.1007\/s10489-022-04047-5","volume":"53","author":"W Shen","year":"2023","unstructured":"Shen W, Rong J, Liu Y, Zhao Y (2023) IrisMarkNet: Iris feature watermarking embedding and extraction network for image copyright protection. Appl Intell 53(9):9992\u201310008","journal-title":"Appl Intell"},{"key":"5917_CR5","doi-asserted-by":"publisher","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. Comput Sci Arxiv Preprint Arxiv 1412 6572. https:\/\/doi.org\/10.48550\/arXiv.1412.6572","DOI":"10.48550\/arXiv.1412.6572"},{"key":"5917_CR6","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.119918","volume":"657","author":"S Guo","year":"2024","unstructured":"Guo S, Li X, Zhu P et al (2024) MixCam-attack: boosting the transferability of adversarial examples with targeted data augmentation. Inf Sci 657:119918","journal-title":"Inf Sci"},{"key":"5917_CR7","doi-asserted-by":"crossref","unstructured":"Moosavidezfooli SM, Fawzi A, Frossard P (2016) DeepFool: a simple and accurate scheme to fool deep neural networks. In: Proc. of the IEEE Conf. on CVPR, Las Vegas, pp 2574\u20132582","DOI":"10.1109\/CVPR.2016.282"},{"key":"5917_CR8","unstructured":"Simonyan K, Zisserman A (2014) Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556"},{"key":"5917_CR9","doi-asserted-by":"crossref","unstructured":"Szegedy C, Vanhoucke V, Ioffe S, Shlens J, Wojna Z (2016) Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 2818\u20132826","DOI":"10.1109\/CVPR.2016.308"},{"key":"5917_CR10","unstructured":"Iandola FN, Han S, Moskewicz MW, Ashraf K, Dally WJ, Keutzer K (2016) SqueezeNet: alexnet-level accuracy with 50x fewer parameters and <\u20090.5 MB model size. arXiv preprint arXiv:1602.07360"},{"key":"5917_CR11","unstructured":"Simonyan K, Zisserman A (2014) Very deep convolutional networks for large-scale image recognition. Computer, Science"},{"key":"5917_CR12","doi-asserted-by":"crossref","unstructured":"Moosavi-dezfooli SM, Fawzi A, Fawzi O (2017) Universal adversarial perturbations, in Proc. CVPR, pp. 1765\u20131773","DOI":"10.1109\/CVPR.2017.17"},{"key":"5917_CR13","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner D (2017) Towards Evaluating the Robustness of Neural Networks. In: 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA, pp. 39\u201357, https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"5917_CR14","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Wu X, Jha S, Swami A (2016) Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP), IEEE, pp. 582\u2013597","DOI":"10.1109\/SP.2016.41"},{"issue":"5","key":"5917_CR15","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su J, Vargas DV, Sakurai K (2019) One pixel attack for fooling deep neural networks. IEEE Trans Evol Comput 23(5):828\u2013841","journal-title":"IEEE Trans Evol Comput"},{"key":"5917_CR16","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1712.04248","author":"B Wieland","year":"2017","unstructured":"Wieland B, Rauber J, Bethge M (2017) Decision-based adversarial attacks: reliable attacks against black-box machine learning models. Proc.  https:\/\/doi.org\/10.48550\/arXiv.1712.04248","journal-title":"Proc"},{"key":"5917_CR17","unstructured":"Engstrom L, Tran B, Tsipras D, Schmidt L, Madry A (2019) Exploring the landscape of spatial robustness. In: International Conference on Machine Learning. pp 1802\u20131811"},{"key":"5917_CR18","doi-asserted-by":"publisher","unstructured":"Schott L, Rauber J, Bethge M,\u00a0Brendel W (2018)\u00a0Towards the first adversarially robust neural network model on MNIST.\u00a0arxiv preprint arxiv:1805.09190. https:\/\/doi.org\/10.48550\/arXiv.1805.09190","DOI":"10.48550\/arXiv.1805.09190"},{"issue":"1","key":"5917_CR19","first-page":"501","volume":"68","author":"Y Xiang","year":"2020","unstructured":"Xiang Y, Xu Y, Li Y, Ma W, Xuan Q, Liu Y (2020) Side-channel gray-ox attack for DNNs, circuits and systems II: Express briefs. IEEE Trans on 68(1):501\u2013505","journal-title":"IEEE Trans on"},{"key":"5917_CR20","doi-asserted-by":"crossref","unstructured":"Jia X, Wei X, Cao X, Han X (2020) Adv-watermark: a novel watermark perturbation for adversarial examples. In: Proc. of the 28th ACM ICMR, pp. 1579\u20131587","DOI":"10.1145\/3394171.3413976"},{"key":"5917_CR21","doi-asserted-by":"publisher","first-page":"119037","DOI":"10.1016\/j.ins.2023.119037","volume":"640","author":"J Liang","year":"2023","unstructured":"Liang J, Feng Z, Chen R, Liu X (2023) Embedded invisible watermark as adversarial example based on Basin-hopping improvement. Sci Inform 640:119037","journal-title":"Sci Inform"},{"key":"5917_CR22","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. pp 770\u2013778","DOI":"10.1109\/CVPR.2016.90"},{"key":"5917_CR23","unstructured":"Fawzi A, Frossard P (2015) Manitest: Are classifiers really invariant, computer science. arxiv preprint arxiv:1507.06535"},{"key":"5917_CR24","doi-asserted-by":"crossref","unstructured":"Kanbak C, Moosavi-Dezfooli SM, Frossard P (2018) Geometric robustness of deep networks: analysis and improvement. In: Proc. of the IEEE Conf. on CVPR, pp. 4441\u20134449","DOI":"10.1109\/CVPR.2018.00467"},{"key":"5917_CR25","doi-asserted-by":"publisher","first-page":"108426","DOI":"10.1016\/j.compeleceng.2022.108426","volume":"104","author":"S Namasudra","year":"2022","unstructured":"Namasudra S (2022) A secure cryptosystem using DNA cryptography and DNA steganography for the cloud-based IoT infrastructure. Comput Electr Eng 104:108426","journal-title":"Comput Electr Eng"},{"key":"5917_CR26","doi-asserted-by":"crossref","unstructured":"Kumar P, Rahman M, Namasudra S et al (2023) Enhancing security of medical images using deep learning, chaotic map, and hash table. Mobile Netw Appl1\u201315","DOI":"10.1007\/s11036-023-02158-y"},{"key":"5917_CR27","doi-asserted-by":"publisher","unstructured":"Namasudra S (2018) Taxonomy of DNA-based security models. In Advances of DNA computing in cryptography. Chapman and Hall\/CRC, pp 37\u201352. https:\/\/doi.org\/10.1201\/9781351011419-3","DOI":"10.1201\/9781351011419-3"},{"key":"5917_CR28","doi-asserted-by":"publisher","first-page":"pp100662","DOI":"10.1016\/j.cosrev.2024.100662","volume":"53","author":"KM Hosny","year":"2024","unstructured":"Hosny KM, Magdi A, ElKomy O, Hamza HM (2024) Digital image watermarking using deep learning: a survey. Comput Sci Rev 53:pp100662","journal-title":"Comput Sci Rev"},{"key":"5917_CR29","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121315","volume":"236","author":"Z Yuan","year":"2024","unstructured":"Yuan Z, Zhang X, Wang Z et al (2024) Semi-fragile neural network watermarking for content authentication and tampering localization. Expert Syst Appl 236:121315","journal-title":"Expert Syst Appl"},{"issue":"20","key":"5917_CR30","doi-asserted-by":"publisher","first-page":"30165","DOI":"10.1007\/s11042-020-08801-0","volume":"80","author":"A Anand","year":"2021","unstructured":"Anand A, Singh AK (2021) Watermarking techniques for medical data authentication: a survey. Multimedia Tools Appl 80(20):30165\u201330197","journal-title":"Multimedia Tools Appl"},{"issue":"22","key":"5917_CR31","doi-asserted-by":"publisher","first-page":"10928","DOI":"10.3390\/app112210928","volume":"11","author":"D Meg\u00edas","year":"2021","unstructured":"Meg\u00edas D, Mazurczyk W (2021) Kuribayashi M data hiding and its applications: digital watermarking and steganography. Applied Sciences 11(22):10928","journal-title":"Applied Sciences"},{"issue":"3","key":"5917_CR32","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1109\/MCE.2017.2684980","volume":"6","author":"SP Mohanty","year":"2017","unstructured":"Mohanty SP, Sengupta A, Guturu P, Kougianos E (2017) Everything you want to know about watermarking from paper marks to hardware protection. IEEE Trans Consumer Electron 6(3):83\u201391","journal-title":"IEEE Trans Consumer Electron"},{"issue":"2","key":"5917_CR33","doi-asserted-by":"publisher","first-page":"415","DOI":"10.3390\/electronics12020415","volume":"12","author":"CC Lin","year":"2023","unstructured":"Lin CC, Lee TL et al (2023) Fragile watermarking for tamper localization and self-recovery based on AMBTC and VQ. Electronics 12(2):415","journal-title":"Electronics"},{"issue":"1","key":"5917_CR34","doi-asserted-by":"publisher","first-page":"264","DOI":"10.1007\/s00034-023-02462-8","volume":"43","author":"A Hammami","year":"2024","unstructured":"Hammami A, Ben Hamida A, Ben Amar C, Nicolas H (2024) Blind semi-fragile hybrid domain-based dual watermarking system for video authentication and tampering localization. Circuits Syst Signal Process 43(1):264\u2013301","journal-title":"Circuits Syst Signal Process"},{"issue":"1","key":"5917_CR35","doi-asserted-by":"publisher","first-page":"1465","DOI":"10.25518\/0037-9565.6178","volume":"85","author":"MS Goli","year":"2016","unstructured":"Goli MS (2016) Naghsh A A comparative study of image-in-image steganography using three schemes of least significant bit. Bulletin de la Soci\u00e9t\u00e9 Royale des Sciences de Li\u00e8ge 85(1):1465\u20131474","journal-title":"Bulletin de la Soci\u00e9t\u00e9 Royale des Sciences de Li\u00e8ge"},{"key":"5917_CR36","doi-asserted-by":"publisher","unstructured":"Das N, Shanbhogue M, Chen S, Hohman F, Chen L, Kounavis ME, Chau DH (2017) Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression. arXiv preprint arXiv:1705.02900. https:\/\/doi.org\/10.48550\/arXiv.1705.02900","DOI":"10.48550\/arXiv.1705.02900"},{"issue":"9","key":"5917_CR37","first-page":"740","volume":"3","author":"A Alhaj","year":"2017","unstructured":"Alhaj A (2017) Combined DWT-DCT digital image watermarking. J Comput Sci 3(9):740\u2013746","journal-title":"J Comput Sci"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-024-05917-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-024-05917-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-024-05917-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,2]],"date-time":"2025-01-02T15:11:12Z","timestamp":1735830672000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-024-05917-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,28]]},"references-count":37,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["5917"],"URL":"https:\/\/doi.org\/10.1007\/s10489-024-05917-w","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,28]]},"assertion":[{"value":"21 October 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 November 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical and informed consent for data used"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"40"}}