{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T18:14:05Z","timestamp":1772907245963,"version":"3.50.1"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2023,6,27]],"date-time":"2023-06-27T00:00:00Z","timestamp":1687824000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,6,27]],"date-time":"2023-06-27T00:00:00Z","timestamp":1687824000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172001"],"award-info":[{"award-number":["62172001"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimed Tools Appl"],"published-print":{"date-parts":[[2024,1]]},"DOI":"10.1007\/s11042-023-15383-0","type":"journal-article","created":{"date-parts":[[2023,6,27]],"date-time":"2023-06-27T15:07:15Z","timestamp":1687878435000},"page":"11215-11227","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Reversible attack based on local visible adversarial perturbation"],"prefix":"10.1007","volume":"83","author":[{"given":"Li","family":"Chen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shaowei","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abel","family":"Andrew","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0387-4806","authenticated-orcid":false,"given":"Zhaoxia","family":"Yin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,6,27]]},"reference":[{"key":"15383_CR1","doi-asserted-by":"publisher","unstructured":"Amin M, Salleh M, Ibrahim S, Katmin M, Shamsuddin M (2003) Information hiding using steganography. In: 4th National conference of telecommunication technology proceedings, pp 21\u201325. https:\/\/doi.org\/10.1109\/NCTT.2003.1188294","DOI":"10.1109\/NCTT.2003.1188294"},{"key":"15383_CR2","unstructured":"Athalye A, Engstrom L, Ilyas A, Kwok K (2018) Synthesizing robust adversarial examples. In: Proceedings of the 35th international conference on machine learning, vol 80, pp 284\u2013293"},{"key":"15383_CR3","unstructured":"Brown TB, Man\u00e9 D, Roy A, Abadi M, Gilmer J (2017) Adversarial patch. In: Neural information processing systems workshops"},{"key":"15383_CR4","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on security and privacy, pp 39\u201357. https:\/\/doi.org\/10.1109\/SP.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"15383_CR5","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: International conference on learning representations"},{"key":"15383_CR6","doi-asserted-by":"publisher","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 770\u2013778. https:\/\/doi.org\/10.1109\/CVPR.2016.90","DOI":"10.1109\/CVPR.2016.90"},{"key":"15383_CR7","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1016\/j.jvcir.2017.11.014","volume":"53","author":"D Hou","year":"2018","unstructured":"Hou D, Qin C, Yu N, Zhang W (2018) Reversible visual transformation via exploring the correlations within color images. J Vis Commun Image Represent 53:134\u2013145. https:\/\/doi.org\/10.1016\/j.jvcir.2017.11.014","journal-title":"J Vis Commun Image Represent"},{"issue":"13","key":"15383_CR8","doi-asserted-by":"publisher","first-page":"800","DOI":"10.1049\/el:20080522","volume":"44","author":"Q Huynh-Thu","year":"2008","unstructured":"Huynh-Thu Q, Ghanbari M (2008) Scope of validity of PSNR in image\/video quality assessment. Electron Lett 44(13):800\u2013801. https:\/\/doi.org\/10.1049\/el:20080522","journal-title":"Electron Lett"},{"key":"15383_CR9","doi-asserted-by":"publisher","unstructured":"Jia X, Wei X, Cao X, Han X (2020) Adv-watermark: a novel watermark perturbation for adversarial examples. In: Proceedings of the 28th ACM international conference on multimedia, pp 1579\u20131587. https:\/\/doi.org\/10.1145\/3394171.3413976","DOI":"10.1145\/3394171.3413976"},{"key":"15383_CR10","unstructured":"Karmon D, Zoran D, Goldberg Y (2018) Lavan: localized and visible adversarial noise. In: International conference on machine learning, pp 2507\u20132515"},{"key":"15383_CR11","unstructured":"Krizhevsky A, Hinton G (2009) Learning multiple layers of features from tiny images"},{"issue":"7553","key":"15383_CR12","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y LeCun","year":"2015","unstructured":"LeCun Y, Bengio Y, Hinton G (2015) Deep learning. Nature 521(7553):436\u2013444. https:\/\/doi.org\/10.1038\/nature14539","journal-title":"Nature"},{"key":"15383_CR13","doi-asserted-by":"publisher","unstructured":"Li CY, Shahin Shamsabadi A, Sanchez-Matilla R, Mazzon R, Cavallaro A (2019) Scene privacy protection. In: Proceedings of the IEEE international conference on acoustics, speech and signal processing (ICASSP), pp 2502\u20132506. https:\/\/doi.org\/10.1109\/ICASSP.2019.8682225","DOI":"10.1109\/ICASSP.2019.8682225"},{"key":"15383_CR14","doi-asserted-by":"publisher","unstructured":"Liu AS, Liu X, Fan J, Ma Y, Zhang A, et al. (2019) Perceptual sensitive gan for generating adversarial patches. In: Proceedings of the AAAI conference on artificial intelligence, vol 33, pp 1028\u20131035, DOI https:\/\/doi.org\/10.1609\/aaai.v33i01.33011028","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"15383_CR15","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli SM, Fawzi A, Fawzi O, Frossard P (2017) Universal adversarial perturbations. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 1765\u20131773. https:\/\/doi.org\/10.1109\/CVPR.2017.17","DOI":"10.1109\/CVPR.2017.17"},{"key":"15383_CR16","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli SM, Fawzi A, Frossard P (2016) Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2574\u20132582. https:\/\/doi.org\/10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"issue":"10","key":"15383_CR17","doi-asserted-by":"publisher","first-page":"2452","DOI":"10.1109\/TPAMI.2018.2861800","volume":"41","author":"KR Mopuri","year":"2018","unstructured":"Mopuri KR, Ganeshan A, Babu RV (2018) Generalizable data-free objective for crafting universal adversarial perturbations. IEEE Trans Pattern Anal Mach Intell 41(10):2452\u20132465. https:\/\/doi.org\/10.1109\/TPAMI.2018.2861800","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"issue":"3","key":"15383_CR18","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1109\/TCSVT.2006.869964","volume":"16","author":"Z Ni","year":"2006","unstructured":"Ni Z, Shi YQ, Ansari N, Su W (2006) Reversible data hiding. IEEE Trans Circuits Syst Video Technol 16(3):354\u2013362. https:\/\/doi.org\/10.1109\/TCSVT.2006.869964","journal-title":"IEEE Trans Circuits Syst Video Technol"},{"key":"15383_CR19","doi-asserted-by":"publisher","unstructured":"Niu JY, Xie ZH, Li Y, Cheng SJ, Fan JW (2021) Scale fusion light cnn for hyperspectral face recognition with knowledge distillation and attention mechanism. Appl Intell, 1\u201315. https:\/\/doi.org\/10.1007\/s10489-021-02721-8","DOI":"10.1007\/s10489-021-02721-8"},{"issue":"7","key":"15383_CR20","doi-asserted-by":"publisher","first-page":"7981","DOI":"10.1007\/s11042-018-6476-5","volume":"78","author":"Z Qu","year":"2019","unstructured":"Qu Z, Cheng Z, Liu W, Wang X (2019) A novel quantum image steganography algorithm based on exploiting modification direction. Multimed Tools Appl 78(7):7981\u20138001. https:\/\/doi.org\/10.1007\/s11042-018-6476-5","journal-title":"Multimed Tools Appl"},{"key":"15383_CR21","doi-asserted-by":"publisher","first-page":"85","DOI":"10.2478\/popets-2021-0006","volume":"1","author":"A Rajabi","year":"2021","unstructured":"Rajabi A, Bobba RB, Rosulek M, Wright C, Feng WC (2021) On the (im)practicality of adversarial perturbation for image privacy. Proc Priv Enhanc Technol 1:85\u2013106. https:\/\/doi.org\/10.2478\/popets-2021-0006","journal-title":"Proc Priv Enhanc Technol"},{"key":"15383_CR22","doi-asserted-by":"publisher","unstructured":"Rao S, Stutz D, Schiele B (2020) Adversarial training against locationoptimized adversarial patches. In: European conference on computer vision, pp 429\u2013448. https:\/\/doi.org\/10.1007\/978-3-030-68238-5_32","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"15383_CR23","doi-asserted-by":"publisher","unstructured":"Ren H, Niu S (2021) Separable reversible data hiding in homomorphic encrypted domain using pob number system. Multimed Tools Appl, 1\u201327. https:\/\/doi.org\/10.1007\/s11042-021-11341-w","DOI":"10.1007\/s11042-021-11341-w"},{"issue":"3","key":"15383_CR24","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky O, Deng J, Su H, Krause J, Satheesh S et al (2015) Imagenet large scale visual recognition challenge. Int J Comput Vis 115 (3):211\u2013252. https:\/\/doi.org\/10.1007\/s11263-015-0816-y","journal-title":"Int J Comput Vis"},{"key":"15383_CR25","doi-asserted-by":"publisher","unstructured":"Santos TI, Abel A, Wilson N, Xu Y (2021) Speaker-independent visual speech recognition with the inception V3 model. In: 2021 IEEE spoken language technology workshop (SLT), pp 613\u2013620. https:\/\/doi.org\/10.1109\/SLT48900.2021.9383540","DOI":"10.1109\/SLT48900.2021.9383540"},{"key":"15383_CR26","doi-asserted-by":"publisher","unstructured":"Shah PG, Yadav AR, Ramani B (2021) Robustness analysis of behavioral cloning-based deep learning models for obstacle mitigation in autonomous vehicles. In: Proceeding of 6th international conference on recent trends in computing, pp 511\u2013523. https:\/\/doi.org\/10.1007\/978-981-33-4501-0_47","DOI":"10.1007\/978-981-33-4501-0_47"},{"key":"15383_CR27","unstructured":"Shan S, Wenger E, Zhang J, Li HY, Zheng HT et al (2020) Fawkes: protecting privacy against unauthorized deep learning models. In: 29th USENIX security symposium, pp 1589\u20131604"},{"key":"15383_CR28","unstructured":"Simonyan K, Zisserman A (2014) Very deep convolutional networks for large-scale image recognition. In: International conference on learning representations"},{"key":"15383_CR29","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D et al (2014) Intriguing properties of neural networks. In: International conference on learning representations"},{"key":"15383_CR30","doi-asserted-by":"publisher","unstructured":"Szegedy C, Vanhoucke V, Ioffe S, Shlens J, Wojna Z (2016) Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2818\u20132826. https:\/\/doi.org\/10.1109\/CVPR.2016.308","DOI":"10.1109\/CVPR.2016.308"},{"issue":"3","key":"15383_CR31","doi-asserted-by":"publisher","first-page":"721","DOI":"10.1109\/TIP.2006.891046","volume":"16","author":"DM Thodi","year":"2007","unstructured":"Thodi DM, Rodriguez JJ (2007) Expansion embedding techniques for reversible watermarking. IEEE Trans Image Process 16(3):721\u2013730. https:\/\/doi.org\/10.1109\/TIP.2006.891046","journal-title":"IEEE Trans Image Process"},{"issue":"4","key":"15383_CR32","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang Z, Bovik AC, Sheikh HR, Simoncelli EP (2004) Image quality assessment: from error visibility to structural similarity. IEEE Trans Image Process 13(4):600\u2013612. https:\/\/doi.org\/10.1109\/TIP.2003.819861","journal-title":"IEEE Trans Image Process"},{"issue":"1","key":"15383_CR33","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1109\/TCSVT.2021.3055072","volume":"32","author":"L Xiong","year":"2021","unstructured":"Xiong L, Han X, Yang CN, Shi YQ (2021) Robust reversible watermarking in encrypted image with secure multi-party based on lightweight cryptography. IEEE Trans Circuits Syst Video Technol 32(1):75\u201391. https:\/\/doi.org\/10.1109\/TCSVT.2021.3055072","journal-title":"IEEE Trans Circuits Syst Video Technol"},{"key":"15383_CR34","doi-asserted-by":"publisher","first-page":"30761","DOI":"10.1007\/s11042-020-10171-6","volume":"80","author":"LM Yan","year":"2020","unstructured":"Yan LM, Chen K, Tong SK, Wang JW, Chen Z (2020) Identifying forged seal imprints using positive and unlabeled learning. Multimed Tools Appl 80:30761\u201330773. https:\/\/doi.org\/10.1007\/s11042-020-10171-6","journal-title":"Multimed Tools Appl"},{"issue":"4","key":"15383_CR35","doi-asserted-by":"publisher","first-page":"1860","DOI":"10.1109\/TCSVT.2021.3084676","volume":"32","author":"Y Yang","year":"2021","unstructured":"Yang Y, Zou T, Huang G, Zhang W (2021) A high visual quality color image reversible data hiding scheme based on b-r-g embedding principle and ciede2000 assessment metric. IEEE Trans Circuits Syst Video Technol 32 (4):1860\u20131874. https:\/\/doi.org\/10.1109\/TCSVT.2021.3084676","journal-title":"IEEE Trans Circuits Syst Video Technol"},{"key":"15383_CR36","unstructured":"Yin Z, Wang H, Chen L, Wang J, Zhang W (2019) Reversible adversarial attack based on reversible image transformation. In: 2021 International workshop on safety & security of deep learning"},{"issue":"8","key":"15383_CR37","doi-asserted-by":"publisher","first-page":"2343","DOI":"10.1109\/TCSVT.2020.2969463","volume":"30","author":"ZX Yin","year":"2020","unstructured":"Yin ZX, Ji Y, Luo B (2020) Reversible data hiding in JPEG images With multi-objective optimization. IEEE Trans Circuits Syst Video Technol 30 (8):2343\u20132352. https:\/\/doi.org\/10.1109\/TCSVT.2020.2969463","journal-title":"IEEE Trans Circuits Syst Video Technol"},{"key":"15383_CR38","doi-asserted-by":"publisher","unstructured":"You Z, Li S, Qian Z, Zhang XP (2021) Reversible privacy-preserving recognition. In: 2021 IEEE International conference on multimedia and expo (ICME), pp 1\u20136. https:\/\/doi.org\/10.1109\/ICME51207.2021.9428115","DOI":"10.1109\/ICME51207.2021.9428115"},{"key":"15383_CR39","doi-asserted-by":"publisher","unstructured":"Yu C, Xue Y, Chen J, Wang Y, Ma H (2021) Enhancing adversarial robustness for image classification by regularizing class level feature distribution. In: IEEE International conference on image processing, pp 494\u2013498. https:\/\/doi.org\/10.1109\/ICIP42928.2021.9506383","DOI":"10.1109\/ICIP42928.2021.9506383"},{"issue":"2","key":"15383_CR40","doi-asserted-by":"publisher","first-page":"3035","DOI":"10.32604\/cmc.2022.022304","volume":"71","author":"XR Zhang","year":"2022","unstructured":"Zhang XR, Sun X, Sun XM, Sun W, SK J (2022) Robust reversible audio watermarking scheme for telemedicine and privacy protection. CMC-Comput Mater Continua 71(2):3035\u20133050. https:\/\/doi.org\/10.32604\/cmc.2022.022304","journal-title":"CMC-Comput Mater Continua"}],"container-title":["Multimedia Tools and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-023-15383-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11042-023-15383-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-023-15383-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,10]],"date-time":"2024-01-10T09:43:04Z","timestamp":1704879784000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11042-023-15383-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,27]]},"references-count":40,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,1]]}},"alternative-id":["15383"],"URL":"https:\/\/doi.org\/10.1007\/s11042-023-15383-0","relation":{},"ISSN":["1380-7501","1573-7721"],"issn-type":[{"value":"1380-7501","type":"print"},{"value":"1573-7721","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,6,27]]},"assertion":[{"value":"10 February 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 May 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 April 2023","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 June 2023","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Competing interests"}}]}}