{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T05:03:08Z","timestamp":1777352588695,"version":"3.51.4"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"10","license":[{"start":{"date-parts":[[2025,5,9]],"date-time":"2025-05-09T00:00:00Z","timestamp":1746748800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,5,9]],"date-time":"2025-05-09T00:00:00Z","timestamp":1746748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/100014718","name":"Innovative Research Group Project of the National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62166008"],"award-info":[{"award-number":["62166008"]}],"id":[{"id":"10.13039\/100014718","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013055","name":"Guizhou Provincial Youth Science and Technology Talents Growth Project","doi-asserted-by":"publisher","award":["QKHPTRC-YQK[2023]028"],"award-info":[{"award-number":["QKHPTRC-YQK[2023]028"]}],"id":[{"id":"10.13039\/501100013055","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2025,7]]},"DOI":"10.1007\/s10489-025-06608-w","type":"journal-article","created":{"date-parts":[[2025,5,9]],"date-time":"2025-05-09T04:16:35Z","timestamp":1746764195000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["DMC-Watermark: A backdoor richer watermark for dual identity verification by dynamic mask covering"],"prefix":"10.1007","volume":"55","author":[{"given":"Yujia","family":"Zhu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruoxi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1715-3324","authenticated-orcid":false,"given":"Daoxun","family":"Xia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,5,9]]},"reference":[{"key":"6608_CR1","doi-asserted-by":"crossref","unstructured":"Yi Sanli, Chen Ziyan, Yi Lunzhao, She Furong (2023) Cas: Breast cancer diagnosis framework based on lesion region recognition in ultrasound images. J King Saud Univ-Comput Inf Sci 35(8)","DOI":"10.1016\/j.jksuci.2023.101707"},{"issue":"4","key":"6608_CR2","doi-asserted-by":"publisher","first-page":"1958","DOI":"10.1109\/TNNLS.2021.3105702","volume":"34","author":"H Liu","year":"2021","unstructured":"Liu H, Ma S, Xia D, Li S (2021) Sfanet: A spectrum-aware feature augmentation network for visible-infrared person reidentification. IEEE Trans Neural Netw Learn Syst 34(4):1958\u20131971","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"6608_CR3","doi-asserted-by":"crossref","unstructured":"\u00c1lvarez-Carmona M\u00c1, Aranda R, Rodr\u00edguez-Gonzalez A, Fajardo-Delgado D, S\u00e1nchez MG, P\u00e9rez-Espinosa H, Mart\u00ednez-Miranda J, Guerrero-Rodr\u00edguez R, Bustio-Mart\u00ednez L, D\u00edaz-Pacheco \u00c1 (2022) Natural language processing applied to tourism research: A systematic review and future research directions. J King Saud Univ-Comput Inf Sci 34(10):10125\u201310144","DOI":"10.1016\/j.jksuci.2022.10.010"},{"key":"6608_CR4","doi-asserted-by":"crossref","unstructured":"Lewis M, Liu Y, Goyal N, Ghazvininejad M, Mohamed A, Levy O, Stoyanov V, Zettlemoyer L (2020) Bart: Denoising sequence-to-sequence pre-training for natural language generation, translation, and comprehension. In Proceedings of the 58th annual meeting of the association for computational linguistics, pp. 7871\u20137880","DOI":"10.18653\/v1\/2020.acl-main.703"},{"key":"6608_CR5","unstructured":"Kim S, Gholami A, Shaw A, Lee N, Mangalam K, Malik J, Mahoney MW, Keutzer K (2022) Squeezeformer: An efficient transformer for automatic speech recognition. Adv Neural Inf Process Syst 35:9361\u20139373"},{"issue":"3","key":"6608_CR6","doi-asserted-by":"publisher","first-page":"202","DOI":"10.1016\/j.jksuci.2023.02.007","volume":"35","author":"DH Yang","year":"2023","unstructured":"Yang DH, Chang JH (2023) Attention-based latent features for jointly trained end-to-end automatic speech recognition with modified speech enhancement. J King Saud Univ-Comput Inf Sci 35(3):202\u2013210","journal-title":"J King Saud Univ-Comput Inf Sci"},{"key":"6608_CR7","doi-asserted-by":"crossref","unstructured":"Uchida Y, Nagai Y, Sakazawa S, Satoh S (2017) Embedding watermarks into deep neural networks. In Proceedings of the 2017 ACM on international conference on multimedia retrieval, pp 269\u2013277","DOI":"10.1145\/3078971.3078974"},{"key":"6608_CR8","doi-asserted-by":"crossref","unstructured":"Wang T, Kerschbaum F (2021) Riga: Covert and robust white-box watermarking of deep neural networks. Proc Web Conf 2021:993\u20131004","DOI":"10.1145\/3442381.3450000"},{"key":"6608_CR9","unstructured":"Adi Y, Baum C, Cisse M, Pinkas B, Keshet J (2018) Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX security symposium (USENIX Security 18), pp 1615\u20131631"},{"key":"6608_CR10","doi-asserted-by":"crossref","unstructured":"Darvish\u00a0Rouhani B, Chen H, Koushanfar F (2019) Deepsigns: An end-to-end watermarking framework for ownership protection of deep neural networks. In Proceedings of the 24th international conference on architectural support for programming languages and operating systems, pp 485\u2013497","DOI":"10.1145\/3297858.3304051"},{"key":"6608_CR11","doi-asserted-by":"crossref","unstructured":"Li Z, Hu C, Zhang Y, Guo S (2019) How to prove your model belongs to you: A blind-watermark based framework to protect intellectual property of dnn. In Proceedings of the 35th annual computer security applications conference, pp 126\u2013137","DOI":"10.1145\/3359789.3359801"},{"key":"6608_CR12","doi-asserted-by":"crossref","unstructured":"Zhang L, Xue M, Zhang LY, Zhang Y, Liu W (2024) An imperceptible and owner-unique watermarking method for graph neural networks. In Proceedings of the ACM turing award celebration conference-China 2024, pp 108\u2013113","DOI":"10.1145\/3674399.3674443"},{"key":"6608_CR13","doi-asserted-by":"crossref","unstructured":"Dai L, Mao J, Liaoran X, Fan X, Zhou X (2024) Secnlp: An nlp classification model watermarking framework based on multi-task learning. Comput Speech Lang 86","DOI":"10.1016\/j.csl.2023.101606"},{"key":"6608_CR14","unstructured":"Gu T, Dolan-Gavitt B, Garg S (2017) Badnets: Identifying vulnerabilities in the machine learning model supply Chain. arXiv\u20131708"},{"key":"6608_CR15","doi-asserted-by":"crossref","unstructured":"Liu Y, Ma S, Aafer Y, Lee WC, Zhai J, Wang W, Zhang X (2018) Trojaning attack on neural networks. In 25th annual network and distributed system security symposium (NDSS). Internet Soc","DOI":"10.14722\/ndss.2018.23291"},{"key":"6608_CR16","unstructured":"Guo J, Potkonjak M (2019) Evolutionary trigger set generation for dnn black-box watermarking. arXiv e-prints, pp arXiv\u20131906"},{"key":"6608_CR17","doi-asserted-by":"publisher","first-page":"2318","DOI":"10.1109\/TIFS.2023.3265535","volume":"18","author":"Y Li","year":"2023","unstructured":"Li Y, Zhu M, Yang X, Jiang Y, Wei T, Xia ST (2023) Black-box dataset ownership verification via backdoor watermarking. IEEE Trans Inf Forensics Secur 18:2318\u20132332","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"6608_CR18","doi-asserted-by":"crossref","unstructured":"Zhu J, Kaplan R, Johnson J, Fei-Fei L (2018) Hidden: Hiding data with deep networks. In Proceedings of the European conference on computer vision (ECCV), pp 657\u2013672","DOI":"10.1007\/978-3-030-01267-0_40"},{"key":"6608_CR19","doi-asserted-by":"crossref","unstructured":"Sinhal R, Jain DK, Ansari IA (2021) Machine learning based blind color image watermarking scheme for copyright protection. Patt Recognit Lett 145:171\u2013177","DOI":"10.1016\/j.patrec.2021.02.011"},{"issue":"8","key":"6608_CR20","first-page":"4005","volume":"44","author":"J Zhang","year":"2021","unstructured":"Zhang J, Chen D, Liao J, Zhang W, Feng H, Hua G, Nenghai Y (2021) Deep model intellectual property protection via deep watermarking. IEEE Trans Pattern Anal Mach Intell 44(8):4005\u20134020","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"issue":"3","key":"6608_CR21","doi-asserted-by":"publisher","first-page":"861","DOI":"10.1007\/s10044-023-01140-4","volume":"26","author":"L Wang","year":"2023","unstructured":"Wang L, Song Y, Xia D (2023) Deep neural network watermarking based on a reversible image hiding network. Pattern Anal Appl 26(3):861\u2013874","journal-title":"Pattern Anal Appl"},{"key":"6608_CR22","doi-asserted-by":"crossref","unstructured":"Zhang J, Dongdong C, Huang Q, Liao J, Zhang W, Feng H, Hua G, Nenghai Y (2022) Poison ink: Robust and invisible backdoor attack. IEEE Trans Image Process 31:5691\u20135705","DOI":"10.1109\/TIP.2022.3201472"},{"key":"6608_CR23","unstructured":"Chen X, Liu C, Li B, Lu K, Song D (2017) Targeted backdoor attacks on deep learning systems using data poisoning. arXiv e-prints, pp arXiv\u20131712"},{"key":"6608_CR24","doi-asserted-by":"crossref","unstructured":"Isola P, Zhu JY, Zhou T, Efros AA (2017) Image-to-image translation with conditional adversarial networks. In Proceedings of the IEEE conference on computer vision and pattern recognition, pp 1125\u20131134","DOI":"10.1109\/CVPR.2017.632"},{"key":"6608_CR25","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1016\/j.procs.2018.05.198","volume":"132","author":"N Sharma","year":"2018","unstructured":"Sharma N, Jain V, Mishra A (2018) An analysis of convolutional neural networks for image classification. Procedia Comput Sci 132:377\u2013384","journal-title":"Procedia Comput Sci"},{"key":"6608_CR26","doi-asserted-by":"crossref","unstructured":"Li LJ, Su H, Lim Y, Fei-Fei L (2012) Objects as attributes for scene classification. In Trends and topics in computer vision: ECCV 2010 Workshops, Heraklion, Crete, Greece, September 10-11, 2010, Revised Selected Papers, Part I 11, Springer, pp 57\u201369","DOI":"10.1007\/978-3-642-35749-7_5"},{"key":"6608_CR27","doi-asserted-by":"crossref","unstructured":"Barni M, Kallas K, Tondi B (2019) A new backdoor attack in cnns by training set corruption without label poisoning. In 2019 IEEE international conference on image processing (ICIP), IEEE, pp 101\u2013105","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"6608_CR28","doi-asserted-by":"crossref","unstructured":"Liu Y, Ma X, Bailey J, Lu F (2020) Reflection backdoor: A natural backdoor attack on deep neural networks. In computer vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part X 16, Springer, pp 182\u2013199","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"6608_CR29","doi-asserted-by":"crossref","unstructured":"Zhong H, Liao C, Squicciarini AC, Zhu S, Miller D (2020) Backdoor embedding in convolutional neural network models via invisible perturbation. In Proceedings of the 10th ACM conference on data and application security and privacy, pp 97\u2013108","DOI":"10.1145\/3374664.3375751"},{"key":"6608_CR30","unstructured":"Wen W, Wu C, Wang Y, Chen Y, Li H (2016) Learning structured sparsity in deep neural networks. Adv Neural Inf Process Syst 29"},{"key":"6608_CR31","doi-asserted-by":"crossref","unstructured":"Van\u00a0Horn G, Mac\u00a0Aodha O, Song Y, Cui Y, Sun C, Shepard A, Adam H, Perona P, Belongie S (2018) The inaturalist species classification and detection dataset. In Proceedings of the IEEE conference on computer vision and pattern recognition, pp 8769\u20138778","DOI":"10.1109\/CVPR.2018.00914"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-025-06608-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-025-06608-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-025-06608-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T13:57:35Z","timestamp":1758290255000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-025-06608-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,9]]},"references-count":31,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2025,7]]}},"alternative-id":["6608"],"URL":"https:\/\/doi.org\/10.1007\/s10489-025-06608-w","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,9]]},"assertion":[{"value":"30 April 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 May 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"733"}}