{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:34:12Z","timestamp":1783791252703,"version":"3.55.0"},"reference-count":94,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2022,11,22]],"date-time":"2022-11-22T00:00:00Z","timestamp":1669075200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,11,22]],"date-time":"2022-11-22T00:00:00Z","timestamp":1669075200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["World Wide Web"],"published-print":{"date-parts":[[2023,7]]},"DOI":"10.1007\/s11280-022-01113-3","type":"journal-article","created":{"date-parts":[[2022,11,23]],"date-time":"2022-11-23T05:13:38Z","timestamp":1669180418000},"page":"1877-1911","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["Intellectual property protection of DNN models"],"prefix":"10.1007","volume":"26","author":[{"given":"Sen","family":"Peng","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yufei","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jie","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zizhuo","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cong","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaohua","family":"Jia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,22]]},"reference":[{"key":"1113_CR1","unstructured":"Zellers, R., Holtzman, A., Rashkin, H., Bisk, Y., Farhadi, A., Roesner, F., Choi, Y.: Defending against neural fake news. In: Wallach, H.M., Larochelle, H., Beygelzimer, A., d\u2019Alch\u00e9-Buc, F., Fox, E.B., Garnett, R. (eds.) Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, Vancouver, pp. 9051\u20139062 (2019)"},{"key":"1113_CR2","doi-asserted-by":"crossref","unstructured":"Goldstein, B.F., Patil, V.C., da Cruz Ferreira, V., Nery, A.S., Fran\u00e7a, F.M.G., Kundu, S.: Preventing DNN model IP theft via hardware obfuscation. IEEE J. Emerg. Sel. Topics Circuits Syst. 11(2), 267\u2013277 (2021)","DOI":"10.1109\/JETCAS.2021.3076151"},{"key":"1113_CR3","unstructured":"Zhou, L., Wen, H., Teodorescu, R., Du, D.H.C.: Distributing deep neural networks with containerized partitions at the edge. In: Ahmad, I., Sundararaman, S. (eds.) 2nd USENIX Workshop on Hot Topics in Edge Computing, HotEdge 2019. USENIX Association, (2019)"},{"key":"1113_CR4","unstructured":"Guo, P., Hu, B., Hu, W.: Mistify: Automating DNN model porting for on-device inference at the edge. In: Mickens, J., Teixeira, R. (eds.) 18th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2021, pp. 705\u2013719. USENIX Association, (2021)"},{"key":"1113_CR5","doi-asserted-by":"publisher","unstructured":"Reisinger, M., Frangoudis, P.A., Dustdar, S.: System support and mechanisms for adaptive edge-to-cloud DNN model serving. In: IEEE International Conference on Cloud Engineering, IC2E 2021, pp. 278\u2013279. IEEE, San Francisco (2021). https:\/\/doi.org\/10.1109\/IC2E52221.2021.00046","DOI":"10.1109\/IC2E52221.2021.00046"},{"key":"1113_CR6","doi-asserted-by":"publisher","unstructured":"Kesarwani, M., Mukhoty, B., Arya, V., Mehta, S.: Model extraction warning in mlaas paradigm. In: Proceedings of the 34th Annual Computer Security Applications Conference, ACSAC 2018, pp. 371\u2013380. ACM, (2018). https:\/\/doi.org\/10.1145\/3274694.3274740","DOI":"10.1145\/3274694.3274740"},{"key":"1113_CR7","doi-asserted-by":"publisher","unstructured":"Hanzlik, L., Zhang, Y., Grosse, K., Salem, A., Augustin, M., Backes, M., Fritz, M.: Mlcapsule: Guarded offline deployment of machine learning as a service. In: IEEE Conference on Computer Vision and Pattern Recognition Workshops, CVPR Workshops 2021, pp. 3300\u20133309. Computer Vision Foundation \/ IEEE, (2021). https:\/\/doi.org\/10.1109\/CVPRW53098.2021.00368","DOI":"10.1109\/CVPRW53098.2021.00368"},{"key":"1113_CR8","doi-asserted-by":"publisher","unstructured":"Sun, Q., Bai, C., Chen, T., Geng, H., Zhang, X., Bai, Y., Yu, B.: Fast and efficient DNN deployment via deep gaussian transfer learning. In: 2021 IEEE\/CVF International Conference on Computer Vision, ICCV 2021, pp. 5360\u20135370. IEEE, (2021). https:\/\/doi.org\/10.1109\/ICCV48922.2021.00533","DOI":"10.1109\/ICCV48922.2021.00533"},{"issue":"7","key":"1113_CR9","doi-asserted-by":"publisher","first-page":"5109","DOI":"10.1007\/s10462-022-10138-z","volume":"55","author":"H Hussain","year":"2022","unstructured":"Hussain, H., Tamizharasan, P.S., Rahul, C.S.: Design possibilities and challenges of DNN models: a review on the perspective of end devices. Artif. Intell. Rev. 55(7), 5109\u20135167 (2022)","journal-title":"Artif. Intell. Rev."},{"issue":"4","key":"1113_CR10","first-page":"49","volume":"16","author":"C Xia","year":"2020","unstructured":"Xia, C., Zhao, J., Cui, H., Feng, X., Xue, J.: Dnntune: Automatic benchmarking DNN models for mobile-cloud computing. ACM Trans. Archit. Code Optim. 16(4), 49\u201314926 (2020)","journal-title":"ACM Trans. Archit. Code Optim."},{"issue":"5786","key":"1113_CR11","doi-asserted-by":"publisher","first-page":"504","DOI":"10.1126\/science.1127647","volume":"313","author":"GE Hinton","year":"2006","unstructured":"Hinton, G.E., Salakhutdinov, R.R.: Reducing the dimensionality of data with neural networks. Science 313(5786), 504\u2013507 (2006). https:\/\/doi.org\/10.1126\/science.1127647","journal-title":"Science"},{"key":"1113_CR12","unstructured":"Yosinski, J., Clune, J., Bengio, Y., Lipson, H.: How transferable are features in deep neural networks? In: Ghahramani, Z., Welling, M., Cortes, C., Lawrence, N.D., Weinberger, K.Q. (eds.) Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems 2014, NIPS 2014, Montreal, pp. 3320\u20133328 (2014)"},{"key":"1113_CR13","unstructured":"Hinton, G., Vinyals, O., Dean, J.: Distilling the knowledge in a neural network (2015). Preprint at arxiv: 1503.02531"},{"key":"1113_CR14","unstructured":"Fang, G., Song, J., Shen, C., Wang, X., Chen, D., Song, M.: Data-Free adversarial distillation. Preprint at arxiv 1912, 11006 (2019)"},{"key":"1113_CR15","doi-asserted-by":"publisher","unstructured":"Choi, Y., Choi, J.P., El-Khamy, M., Lee, J.: Data-free network quantization with adversarial knowledge distillation. In: 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR Workshops 2020, pp. 3047\u20133057. Computer Vision Foundation \/ IEEE, (2020). https:\/\/doi.org\/10.1109\/CVPRW50498.2020.00363","DOI":"10.1109\/CVPRW50498.2020.00363"},{"key":"1113_CR16","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction apis. In: Holz, T., Savage, S. (eds.) 25th USENIX Security Symposium, USENIX Security 16, pp. 601\u2013618. USENIX Association, (2016)"},{"key":"1113_CR17","doi-asserted-by":"publisher","unstructured":"Orekondy, T., Schiele, B., Fritz, M.: Knockoff nets: Stealing functionality of black-box models. In: IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2019, pp. 4954\u20134963. Computer Vision Foundation \/ IEEE, (2019). https:\/\/doi.org\/10.1109\/CVPR.2019.00509","DOI":"10.1109\/CVPR.2019.00509"},{"key":"1113_CR18","doi-asserted-by":"crossref","unstructured":"Yu, H., Yang, K., Zhang, T., Tsai, Y., Ho, T., Jin, Y.: Cloudleak: Large-scale deep learning models stealing through adversarial examples. In: 27th Annual Network and Distributed System Security Symposium, NDSS 2020. The Internet Society, (2020)","DOI":"10.14722\/ndss.2020.24178"},{"key":"1113_CR19","doi-asserted-by":"publisher","unstructured":"Kariyappa, S., Prakash, A., Qureshi, M.K.: MAZE: data-free model stealing attack using zeroth-order gradient estimation. In: IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2021, pp. 13814\u201313823. Computer Vision Foundation \/ IEEE, (2021). https:\/\/doi.org\/10.1109\/CVPR46437.2021.01360","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"1113_CR20","doi-asserted-by":"crossref","unstructured":"Sanyal, S., Addepalli, S., Babu, R.V.: Towards data-free model stealing in a hard label setting. In: 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, pp. 13430\u201313439. Computer Vision Foundation \/ IEEE, (2022)","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"1113_CR21","doi-asserted-by":"publisher","unstructured":"Rakin, A.S., Chowdhuryy, M.H.I., Yao, F., Fan, D.: Deepsteal: Advanced model extractions leveraging efficient weight stealing in memories. In: 43rd IEEE Symposium on Security and Privacy, SP 2022, pp. 1157\u20131174. IEEE, (2022). https:\/\/doi.org\/10.1109\/SP46214.2022.9833743","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"1113_CR22","doi-asserted-by":"publisher","unstructured":"Milli, S., Schmidt, L., Dragan, A.D., Hardt, M.: Model reconstruction from model explanations. In: danah boyd, Morgenstern, J.H. (eds.) Proceedings of the Conference on Fairness, Accountability, and Transparency, FAT 2019, pp. 1\u20139. ACM, (2019). https:\/\/doi.org\/10.1145\/3287560.3287562","DOI":"10.1145\/3287560.3287562"},{"key":"1113_CR23","unstructured":"Batina, L., Bhasin, S., Jap, D., Picek, S.: CSI NN: reverse engineering of neural network architectures through electromagnetic side channel. In: Heninger, N., Traynor, P. (eds.) 28th USENIX Security Symposium, USENIX Security 2019, pp. 515\u2013532. USENIX Association, (2019)"},{"issue":"13","key":"1113_CR24","doi-asserted-by":"publisher","first-page":"9233","DOI":"10.1007\/s00521-019-04434-z","volume":"32","author":"EL Merrer","year":"2020","unstructured":"Merrer, E.L., P\u00e9rez, P., Tr\u00e9dan, G.: Adversarial frontier stitching for remote neural network watermarking. Neural Comput. Appl. 32(13), 9233\u20139244 (2020)","journal-title":"Neural Comput. Appl."},{"key":"1113_CR25","doi-asserted-by":"publisher","unstructured":"Yang, P., Lao, Y., Li, P.: Robust watermarking for deep neural networks via bi-level optimization. In: 2021 IEEE\/CVF International Conference on Computer Vision, ICCV 2021, pp. 14821\u201314830. IEEE, (2021). https:\/\/doi.org\/10.1109\/ICCV48922.2021.01457","DOI":"10.1109\/ICCV48922.2021.01457"},{"key":"1113_CR26","unstructured":"Adi, Y., Baum, C., Ciss\u00e9, M., Pinkas, B., Keshet, J.: Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In: Enck, W., Felt, A.P. (eds.) 27th USENIX Security Symposium, USENIX Security 2018, pp. 1615\u20131631. USENIX Association, (2018)"},{"key":"1113_CR27","doi-asserted-by":"publisher","unstructured":"Zhang, J., Gu, Z., Jang, J., Wu, H., Stoecklin, M.P., Huang, H., Molloy, I.M.: Protecting intellectual property of deep neural networks with watermarking. In: Kim, J., Ahn, G., Kim, S., Kim, Y., L\u00f3pez, J., Kim, T. (eds.) Proceedings of the 2018 on Asia Conference on Computer and Communications Security, AsiaCCS 2018, pp. 159\u2013172. ACM, (2018). https:\/\/doi.org\/10.1145\/3196494.3196550","DOI":"10.1145\/3196494.3196550"},{"key":"1113_CR28","doi-asserted-by":"publisher","unstructured":"Guo, J., Potkonjak, M.: Watermarking deep neural networks for embedded systems. In: Bahar, I. (ed.) Proceedings of the International Conference on Computer-Aided Design, ICCAD 2018, p. 133. ACM, (2018). https:\/\/doi.org\/10.1145\/3240765.3240862","DOI":"10.1145\/3240765.3240862"},{"key":"1113_CR29","doi-asserted-by":"publisher","unstructured":"Li, Z., Hu, C., Zhang, Y., Guo, S.: How to prove your model belongs to you: a blind-watermark based framework to protect intellectual property of DNN. In: Balenson, D. (ed.) Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC 2019, pp. 126\u2013137. ACM, (2019). https:\/\/doi.org\/10.1145\/3359789.3359801","DOI":"10.1145\/3359789.3359801"},{"key":"1113_CR30","doi-asserted-by":"publisher","unstructured":"Lukas, N., Jiang, E., Li, X., Kerschbaum, F.: Sok: How robust is image classification deep neural network watermarking? In: 43rd IEEE Symposium on Security and Privacy, SP 2022, pp. 787\u2013804. IEEE, (2022). https:\/\/doi.org\/10.1109\/SP46214.2022.9833693","DOI":"10.1109\/SP46214.2022.9833693"},{"key":"1113_CR31","doi-asserted-by":"publisher","unstructured":"Shafieinejad, M., Lukas, N., Wang, J., Li, X., Kerschbaum, F.: On the robustness of backdoor-based watermarking in deep neural networks. In: Borghys, D., Bas, P., Verdoliva, L., Pevn\u00fd, T., Li, B., Newman, J. (eds.) Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security, pp. 177\u2013188. ACM, (2021). https:\/\/doi.org\/10.1145\/3437880.3460401","DOI":"10.1145\/3437880.3460401"},{"key":"1113_CR32","doi-asserted-by":"publisher","unstructured":"Guo, S., Zhang, T., Qiu, H., Zeng, Y., Xiang, T., Liu, Y.: Fine-tuning is not enough: A simple yet effective watermark removal attack for DNN models. In: Zhou, Z. (ed.) Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence, IJCAI 2021, pp. 3635\u20133641. ijcai.org, (2021). https:\/\/doi.org\/10.24963\/ijcai.2021\/500","DOI":"10.24963\/ijcai.2021\/500"},{"key":"1113_CR33","unstructured":"Hitaj, D., Mancini, L.V.: Have You Stolen My Model? Evasion attacks against deep neural network watermarking techniques. Preprint at arxiv: 1809.00615 (2018)"},{"key":"1113_CR34","doi-asserted-by":"publisher","unstructured":"Wang, T., Kerschbaum, F.: Attacks on digital watermarks for deep neural networks. In: IEEE International Conference on Acoustics, Speech and Signal Processing, ICASSP 2019, pp. 2622\u20132626. IEEE, (2019). https:\/\/doi.org\/10.1109\/ICASSP.2019.8682202","DOI":"10.1109\/ICASSP.2019.8682202"},{"key":"1113_CR35","doi-asserted-by":"publisher","unstructured":"Chen, J., Wang, J., Peng, T., Sun, Y., Cheng, P., Ji, S., Ma, X., Li, B., Song, D.: Copy, right? a testing framework for copyright protection of deep learning models. In: 43rd IEEE Symposium on Security and Privacy, SP 2022, pp. 824\u2013841. IEEE, (2022). https:\/\/doi.org\/10.1109\/SP46214.2022.9833747","DOI":"10.1109\/SP46214.2022.9833747"},{"key":"1113_CR36","unstructured":"Goodfellow, I., Bengio, Y., Courville, A.: Deep Learning. MIT Press, (2016)"},{"key":"1113_CR37","doi-asserted-by":"publisher","unstructured":"Devlin, J., Chang, M., Lee, K., Toutanova, K.: BERT: pre-training of deep bidirectional transformers for language understanding. In: Burstein, J., Doran, C., Solorio, T. (eds.) Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, NAACL-HLT 2019, pp. 4171\u20134186. Association for Computational Linguistics, (2019). https:\/\/doi.org\/10.18653\/v1\/n19-1423","DOI":"10.18653\/v1\/n19-1423"},{"key":"1113_CR38","unstructured":"Cheng, Y., Wang, D., Zhou, P., Zhang, T.: A survey of model compression and acceleration for deep neural networks. Preprint at arxiv: 1710.09282 (2017)"},{"issue":"7","key":"1113_CR39","doi-asserted-by":"publisher","first-page":"5113","DOI":"10.1007\/s10462-020-09816-7","volume":"53","author":"T Choudhary","year":"2020","unstructured":"Choudhary, T., Mishra, V.K., Goswami, A., Sarangapani, J.: A comprehensive survey on model compression and acceleration. Artif. Intell. Rev. 53(7), 5113\u20135155 (2020)","journal-title":"Artif. Intell. Rev."},{"key":"1113_CR40","unstructured":"LeCun, Y., Denker, J.S., Solla, S.A.: Optimal brain damage. In: Touretzky, D.S. (ed.) Advances in Neural Information Processing Systems 2, NIPS 1989, pp. 598\u2013605. Morgan Kaufmann, (1989)"},{"key":"1113_CR41","unstructured":"Han, S., Pool, J., Tran, J., Dally, W.J.: Learning both weights and connections for efficient neural network. In: Cortes, C., Lawrence, N.D., Lee, D.D., Sugiyama, M., Garnett, R. (eds.) Advances in Neural Information Processing Systems 28: Annual Conference on Neural Information Processing Systems 2015, NIPS 2015, Montreal, pp. 1135\u20131143 (2015)"},{"key":"1113_CR42","unstructured":"Li, H., Kadav, A., Durdanovic, I., Samet, H., Graf, H.P.: Pruning filters for efficient convnets. In: 5th International Conference on Learning Representations, ICLR 2017. OpenReview.net, (2017)"},{"key":"1113_CR43","unstructured":"Polino, A., Pascanu, R., Alistarh, D.: Model compression via distillation and quantization. In: 6th International Conference on Learning Representations, ICLR 2018. OpenReview.net, (2018)"},{"key":"1113_CR44","doi-asserted-by":"publisher","unstructured":"Rigamonti, R., Sironi, A., Lepetit, V., Fua, P.: Learning separable filters. In: 2013 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2013, pp. 2754\u20132761. IEEE Computer Society, (2013). https:\/\/doi.org\/10.1109\/CVPR.2013.355","DOI":"10.1109\/CVPR.2013.355"},{"key":"1113_CR45","unstructured":"Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., Papernot, N.: High accuracy and high fidelity extraction of neural networks. In: Capkun, S., Roesner, F. (eds.) 29th USENIX Security Symposium, USENIX Security 2020, pp. 1345\u20131362. USENIX Association, (2020)"},{"issue":"12","key":"1113_CR46","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1109\/MCOM.001.2000196","volume":"58","author":"X Gong","year":"2020","unstructured":"Gong, X., Wang, Q., Chen, Y., Yang, W., Jiang, X.: Model extraction attacks and defenses on cloud-based machine learning models. IEEE Commun. Mag. 58(12), 83\u201389 (2020)","journal-title":"IEEE Commun. Mag."},{"key":"1113_CR47","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1016\/j.neucom.2021.07.051","volume":"461","author":"Y Li","year":"2021","unstructured":"Li, Y., Wang, H., Barni, M.: A survey of deep neural network watermarking techniques. Neurocomputing 461, 171\u2013193 (2021)","journal-title":"Neurocomputing"},{"key":"1113_CR48","doi-asserted-by":"publisher","unstructured":"Uchida, Y., Nagai, Y., Sakazawa, S., Satoh, S.: Embedding watermarks into deep neural networks. In: Ionescu, B., Sebe, N., Feng, J., Larson, M.A., Lienhart, R., Snoek, C. (eds.) Proceedings of the 2017 ACM on International Conference on Multimedia Retrieval, ICMR 2017, pp. 269\u2013277. ACM, (2017). https:\/\/doi.org\/10.1145\/3078971.3078974","DOI":"10.1145\/3078971.3078974"},{"key":"1113_CR49","doi-asserted-by":"publisher","unstructured":"Chen, H., Rouhani, B.D., Fu, C., Zhao, J., Koushanfar, F.: Deepmarks: A secure fingerprinting framework for digital rights management of deep learning models. In: El-Saddik, A., Bimbo, A.D., Zhang, Z., Hauptmann, A.G., Candan, K.S., Bertini, M., Xie, L., Wei, X. (eds.) Proceedings of the 2019 on International Conference on Multimedia Retrieval, ICMR 2019, pp. 105\u2013113. ACM, (2019). https:\/\/doi.org\/10.1145\/3323873.3325042","DOI":"10.1145\/3323873.3325042"},{"key":"1113_CR50","doi-asserted-by":"publisher","unstructured":"Wang, T., Kerschbaum, F.: RIGA: covert and robust white-box watermarking of deep neural networks. In: Leskovec, J., Grobelnik, M., Najork, M., Tang, J., Zia, L. (eds.) Proceedings of the Web Conference 2021, WWW 2021, pp. 993\u20131004. ACM \/ IW3C2, (2021). https:\/\/doi.org\/10.1145\/3442381.3450000","DOI":"10.1145\/3442381.3450000"},{"key":"1113_CR51","unstructured":"Liu, H., Weng, Z., Zhu, Y.: Watermarking deep neural networks with greedy residuals. In: Meila, M., Zhang, T. (eds.) Proceedings of the 38th International Conference on Machine Learning, ICML 2021. Proceedings of Machine Learning Research, vol. 139, pp. 6978\u20136988. PMLR, (2021)"},{"key":"1113_CR52","doi-asserted-by":"publisher","unstructured":"Rouhani, B.D., Chen, H., Koushanfar, F.: Deepsigns: An end-to-end watermarking framework for ownership protection of deep neural networks. In: Bahar, I., Herlihy, M., Witchel, E., Lebeck, A.R. (eds.) Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS 2019, pp. 485\u2013497. ACM, (2019). https:\/\/doi.org\/10.1145\/3297858.3304051","DOI":"10.1145\/3297858.3304051"},{"key":"1113_CR53","doi-asserted-by":"publisher","unstructured":"Namba, R., Sakuma, J.: Robust watermarking of neural network with exponential weighting. In: Galbraith, S.D., Russello, G., Susilo, W., Gollmann, D., Kirda, E., Liang, Z. (eds.) Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, AsiaCCS 2019, pp. 228\u2013240. ACM, (2019). https:\/\/doi.org\/10.1145\/3321705.3329808","DOI":"10.1145\/3321705.3329808"},{"key":"1113_CR54","unstructured":"Jia, H., Choquette-Choo, C.A., Chandrasekaran, V., Papernot, N.: Entangled watermarks as a defense against model extraction. In: Bailey, M., Greenstadt, R. (eds.) 30th USENIX Security Symposium, USENIX Security 2021, pp. 1937\u20131954. USENIX Association, (2021)"},{"key":"1113_CR55","doi-asserted-by":"publisher","unstructured":"Szyller, S., Atli, B.G., Marchal, S., Asokan, N.: DAWN: dynamic adversarial watermarking of neural networks. In: Shen, H.T., Zhuang, Y., Smith, J.R., Yang, Y., Cesar, P., Metze, F., Prabhakaran, B. (eds.) Proceedings of the 29th ACM International Conference on Multimedia, MM 2021, pp. 4417\u20134425. ACM, (2021). https:\/\/doi.org\/10.1145\/3474085.3475591","DOI":"10.1145\/3474085.3475591"},{"key":"1113_CR56","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: Bengio, Y., LeCun, Y. (eds.) 3rd International Conference on Learning Representations, ICLR 2015, San Diego (2015)"},{"key":"1113_CR57","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. In: 5th International Conference on Learning Representations, ICLR 2017. OpenReview.net, (2017)"},{"key":"1113_CR58","unstructured":"Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., Madry, A.: Adversarial examples are not bugs, they are features. In: Wallach, H.M., Larochelle, H., Beygelzimer, A., d\u2019Alch\u00e9-Buc, F., Fox, E.B., Garnett, R. (eds.) Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, Vancouver, pp. 125\u2013136 (2019)"},{"key":"1113_CR59","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: BadNets: Identifying vulnerabilities in the machine learning model supply chain. Preprint at https:\/\/arxiv.org\/abs\/1708.06733 (2017)"},{"key":"1113_CR60","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, S., Aafer, Y., Lee, W., Zhai, J., Wang, W., Zhang, X.: Trojaning attack on neural networks. In: 25th Annual Network and Distributed System Security Symposium, NDSS 2018. The Internet Society, (2018)","DOI":"10.14722\/ndss.2018.23291"},{"key":"1113_CR61","doi-asserted-by":"publisher","unstructured":"Jia, H., Yaghini, M., Choquette-Choo, C.A., Dullerud, N., Thudi, A., Chandrasekaran, V., Papernot, N.: Proof-of-learning: Definitions and practice. In: 42nd IEEE Symposium on Security and Privacy, SP 2021, pp. 1039\u20131056. IEEE, (2021). https:\/\/doi.org\/10.1109\/SP40001.2021.00106","DOI":"10.1109\/SP40001.2021.00106"},{"key":"1113_CR62","doi-asserted-by":"publisher","unstructured":"Cao, X., Jia, J., Gong, N.Z.: Ipguard: Protecting intellectual property of deep neural networks via fingerprinting the classification boundary. In: Cao, J., Au, M.H., Lin, Z., Yung, M. (eds.) Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, AsiaCCS 2021, pp. 14\u201325. ACM, (2021). https:\/\/doi.org\/10.1145\/3433210.3437526","DOI":"10.1145\/3433210.3437526"},{"key":"1113_CR63","unstructured":"Lukas, N., Zhang, Y., Kerschbaum, F.: Deep neural network fingerprinting by conferrable adversarial examples. In: 9th International Conference on Learning Representations, ICLR 2021. OpenReview.net, (2021)"},{"key":"1113_CR64","doi-asserted-by":"crossref","unstructured":"Peng, Z., Li, S., Chen, G., Zhang, C., Zhu, H., Xue, M.: Fingerprinting deep neural networks globally via universal adversarial perturbations. In: 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, pp. 13430\u201313439. Computer Vision Foundation \/ IEEE, (2022)","DOI":"10.1109\/CVPR52688.2022.01307"},{"key":"1113_CR65","doi-asserted-by":"publisher","unstructured":"Li, Y., Zhang, Z., Liu, B., Yang, Z., Liu, Y.: Modeldiff: Testing-based DNN similarity comparison for model reuse detection. In: Cadar, C., Zhang, X. (eds.) Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2021, pp. 139\u2013151. ACM, (2021). https:\/\/doi.org\/10.1145\/3460319.3464816","DOI":"10.1145\/3460319.3464816"},{"key":"1113_CR66","unstructured":"Maini, P., Yaghini, M., Papernot, N.: Dataset inference: Ownership resolution in machine learning. In: 9th International Conference on Learning Representations, ICLR 2021. OpenReview.net, (2021)"},{"key":"1113_CR67","doi-asserted-by":"publisher","unstructured":"Chen, H., Fu, C., Rouhani, B.D., Zhao, J., Koushanfar, F.: Deepattest: An end-to-end attestation framework for deep neural networks. In: Manne, S.B., Hunter, H.C., Altman, E.R. (eds.) Proceedings of the 46th International Symposium on Computer Architecture, ISCA 2019, pp. 487\u2013498. ACM, (2019). https:\/\/doi.org\/10.1145\/3307650.3322251","DOI":"10.1145\/3307650.3322251"},{"key":"1113_CR68","doi-asserted-by":"publisher","unstructured":"Chakraborty, A., Mondal, A., Srivastava, A.: Hardware-assisted intellectual property protection of deep learning models. In: 57th ACM\/IEEE Design Automation Conference, DAC 2020, pp. 1\u20136. IEEE, (2020). https:\/\/doi.org\/10.1109\/DAC18072.2020.9218651","DOI":"10.1109\/DAC18072.2020.9218651"},{"key":"1113_CR69","unstructured":"Fan, L., Ng, K.W., Chan, C.S.: Rethinking deep neural network ownership verification: embedding passports to defeat ambiguity attacks. In: Wallach, H.M., Larochelle, H., Beygelzimer, A., d\u2019Alch\u00e9-Buc, F., Fox, E.B., Garnett, R. (eds.) Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, Vancouver, pp. 4716\u20134725 (2019)"},{"key":"1113_CR70","unstructured":"Zhang, J., Chen, D., Liao, J., Zhang, W., Hua, G., Yu, N.: Passport-aware normalization for deep model protection. In: Larochelle, H., Ranzato, M., Hadsell, R., Balcan, M., Lin, H. (eds.) Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020 (2020)"},{"key":"1113_CR71","doi-asserted-by":"crossref","unstructured":"Lin, N., Chen, X., Lu, H., Li, X.: Chaotic weights: A novel approach to protect intellectual property of deep neural networks. IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 40(7), 1327\u20131339 (2021)","DOI":"10.1109\/TCAD.2020.3018403"},{"key":"1113_CR72","unstructured":"Xue, M., Sun, S., He, C., Zhang, Y., Wang, J., Liu, W.: ActiveGuard: An active DNN IP protection technique via adversarial examples. Preprint at arxiv: 2103.01527 (2021)"},{"key":"1113_CR73","doi-asserted-by":"publisher","unstructured":"Lee, T., Edwards, B., Molloy, I.M., Su, D.: Defending against neural network model stealing attacks using deceptive perturbations. In: 2019 IEEE Security and Privacy Workshops, SP Workshops 2019, pp. 43\u201349. IEEE, (2019). https:\/\/doi.org\/10.1109\/SPW.2019.00020","DOI":"10.1109\/SPW.2019.00020"},{"key":"1113_CR74","unstructured":"Orekondy, T., Schiele, B., Fritz, M.: Prediction poisoning: Towards defenses against DNN model stealing attacks. In: 8th International Conference on Learning Representations, ICLR 2020. OpenReview.net, (2020)"},{"key":"1113_CR75","doi-asserted-by":"publisher","unstructured":"Juuti, M., Szyller, S., Marchal, S., Asokan, N.: PRADA: protecting against DNN model stealing attacks. In: IEEE European Symposium on Security and Privacy, EuroS &P 2019, pp. 512\u2013527. IEEE, (2019). https:\/\/doi.org\/10.1109\/EuroSP.2019.00044","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"1113_CR76","doi-asserted-by":"publisher","unstructured":"Kariyappa, S., Qureshi, M.K.: Defending against model stealing attacks with adaptive misinformation. In: 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2020, pp. 767\u2013775. Computer Vision Foundation \/ IEEE, (2020). https:\/\/doi.org\/10.1109\/CVPR42600.2020.00085","DOI":"10.1109\/CVPR42600.2020.00085"},{"issue":"2","key":"1113_CR77","doi-asserted-by":"publisher","first-page":"180","DOI":"10.1049\/cit2.12029","volume":"6","author":"F Regazzoni","year":"2021","unstructured":"Regazzoni, F., Palmieri, P., Smailbegovic, F., Cammarota, R., Polian, I.: Protecting artificial intelligence ips: a survey of watermarking and fingerprinting for machine learning. CAAI Transactions on Intelligence Technology 6(2), 180\u2013191 (2021)","journal-title":"CAAI Transactions on Intelligence Technology"},{"key":"1113_CR78","doi-asserted-by":"publisher","unstructured":"Barni, M., P\u00e9rez-Gonz\u00e1lez, F., Tondi, B.: DNN watermarking: Four challenges and a funeral. In: Borghys, D., Bas, P., Verdoliva, L., Pevn\u00fd, T., Li, B., Newman, J. (eds.) Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security, pp. 189\u2013196. ACM, (2021). https:\/\/doi.org\/10.1145\/3437880.3460399","DOI":"10.1145\/3437880.3460399"},{"key":"1113_CR79","doi-asserted-by":"publisher","unstructured":"Xue, M., Wang, J., Liu, W.: Dnn intellectual property protection: Taxonomy, attacks and evaluations. In: Chen, Y., Zhirnov, V.V., Sasan, A., Savidis, I. (eds.) Proceedings of the 2021 on Great Lakes Symposium on VLSI, GLSVLSI 2021, pp. 455\u2013460. ACM, (2021). https:\/\/doi.org\/10.1145\/3453688.3461752","DOI":"10.1145\/3453688.3461752"},{"issue":"1","key":"1113_CR80","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s13735-018-0147-1","volume":"7","author":"Y Nagai","year":"2018","unstructured":"Nagai, Y., Uchida, Y., Sakazawa, S., Satoh, S.: Digital watermarking for deep neural networks. Int. J. Multim. Inf. Retr. 7(1), 3\u201316 (2018)","journal-title":"Int. J. Multim. Inf. Retr."},{"key":"1113_CR81","doi-asserted-by":"publisher","unstructured":"Chen, X., Wang, W., Bender, C., Ding, Y., Jia, R., Li, B., Song, D.: REFIT: A unified watermark removal framework for deep learning systems with limited data. In: Cao, J., Au, M.H., Lin, Z., Yung, M. (eds.) Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, ASIA CCS 2021, pp. 321\u2013335. ACM, (2021). https:\/\/doi.org\/10.1145\/3433210.3453079","DOI":"10.1145\/3433210.3453079"},{"key":"1113_CR82","unstructured":"Kornblith, S., Norouzi, M., Lee, H., Hinton, G.E.: Similarity of neural network representations revisited. In: Chaudhuri, K., Salakhutdinov, R. (eds.) Proceedings of the 36th International Conference on Machine Learning, ICML 2019. Proceedings of Machine Learning Research, vol. 97, pp. 3519\u20133529. PMLR, (2019)"},{"key":"1113_CR83","unstructured":"Salakhutdinov, R., Hinton, G.E.: Learning a nonlinear embedding by preserving class neighbourhood structure. In: Meila, M., Shen, X. (eds.) Proceedings of the Eleventh International Conference on Artificial Intelligence and Statistics, AISTATS 2007. JMLR Proceedings, vol. 2, pp. 412\u2013419. JMLR.org, (2007)"},{"key":"1113_CR84","doi-asserted-by":"publisher","unstructured":"Breier, J., Hou, X., Jap, D., Ma, L., Bhasin, S., Liu, Y.: Practical fault attack on deep neural networks. In: Lie, D., Mannan, M., Backes, M., Wang, X. (eds.) Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS 2018, pp. 2204\u20132206. ACM, (2018). https:\/\/doi.org\/10.1145\/3243734.3278519","DOI":"10.1145\/3243734.3278519"},{"key":"1113_CR85","unstructured":"Hong, S., Frigo, P., Kaya, Y., Giuffrida, C., Dumitras, T.: Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks. In: Heninger, N., Traynor, P. (eds.) 28th USENIX Security Symposium, USENIX Security 2019, pp. 497\u2013514. USENIX Association, (2019)"},{"key":"1113_CR86","doi-asserted-by":"publisher","unstructured":"Zhang, R., Liu, J., Ding, Y., Wang, Z., Wu, Q., Ren, K.: Adversarial examples for proof-of-learning. In: 43rd IEEE Symposium on Security and Privacy, SP 2022, pp. 1408\u20131422. IEEE, (2022). https:\/\/doi.org\/10.1109\/SP46214.2022.9833596","DOI":"10.1109\/SP46214.2022.9833596"},{"key":"1113_CR87","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli, S., Fawzi, A., Fawzi, O., Frossard, P.: Universal adversarial perturbations. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017, pp. 86\u201394. IEEE Computer Society, (2017). https:\/\/doi.org\/10.1109\/CVPR.2017.17","DOI":"10.1109\/CVPR.2017.17"},{"key":"1113_CR88","doi-asserted-by":"publisher","unstructured":"Cai, Y., Chen, X., Tian, L., Wang, Y., Yang, H.: Enabling secure in-memory neural network computing by sparse fast gradient encryption. In: Pan, D.Z. (ed.) Proceedings of the International Conference on Computer-Aided Design, ICCAD 2019, pp. 1\u20138. ACM, (2019). https:\/\/doi.org\/10.1109\/ICCAD45719.2019.8942041","DOI":"10.1109\/ICCAD45719.2019.8942041"},{"key":"1113_CR89","first-page":"1","volume":"45","author":"G Peterson","year":"1997","unstructured":"Peterson, G.: Arnold\u2019s cat map. Math linear algebra 45, 1\u20137 (1997)","journal-title":"Arnold\u2019s cat map. Math linear algebra"},{"key":"1113_CR90","doi-asserted-by":"publisher","unstructured":"Papernot, N., McDaniel, P.D., Goodfellow, I.J., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: Karri, R., Sinanoglu, O., Sadeghi, A., Yi, X. (eds.) Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, AsiaCCS 2017, pp. 506\u2013519. ACM, (2017). https:\/\/doi.org\/10.1145\/3052973.3053009","DOI":"10.1145\/3052973.3053009"},{"issue":"5","key":"1113_CR91","doi-asserted-by":"publisher","first-page":"1852","DOI":"10.1109\/TNNLS.2020.2991378","volume":"32","author":"Y Quan","year":"2021","unstructured":"Quan, Y., Teng, H., Chen, Y., Ji, H.: Watermarking deep neural networks in image processing. IEEE Trans. Neural Networks Learn. Syst. 32(5), 1852\u20131865 (2021)","journal-title":"IEEE Trans. Neural Networks Learn. Syst."},{"key":"1113_CR92","doi-asserted-by":"publisher","unstructured":"Ong, D.S., Chan, C.S., Ng, K.W., Fan, L., Yang, Q.: Protecting intellectual property of generative adversarial networks from ambiguity attacks. In: IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2021, pp. 3630\u20133639. Computer Vision Foundation \/ IEEE, (2021). https:\/\/doi.org\/10.1109\/CVPR46437.2021.00363","DOI":"10.1109\/CVPR46437.2021.00363"},{"key":"1113_CR93","doi-asserted-by":"publisher","unstructured":"Zhao, X., Wu, H., Zhang, X.: Watermarking graph neural networks by random graphs. In: Varol, A., Karabatak, M., Varol, I. (eds.) 9th International Symposium on Digital Forensics and Security, ISDFS 2021, pp. 1\u20136. IEEE, (2021). https:\/\/doi.org\/10.1109\/ISDFS52919.2021.9486352","DOI":"10.1109\/ISDFS52919.2021.9486352"},{"key":"1113_CR94","unstructured":"Xu, J., Picek, S.: Watermarking Graph Neural Networks based on Backdoor Attacks. Preprint at arxiv: 2110.11024 (2021)"}],"container-title":["World Wide Web"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-022-01113-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11280-022-01113-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-022-01113-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,26]],"date-time":"2023-07-26T14:42:50Z","timestamp":1690382570000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11280-022-01113-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,22]]},"references-count":94,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,7]]}},"alternative-id":["1113"],"URL":"https:\/\/doi.org\/10.1007\/s11280-022-01113-3","relation":{},"ISSN":["1386-145X","1573-1413"],"issn-type":[{"value":"1386-145X","type":"print"},{"value":"1573-1413","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,22]]},"assertion":[{"value":"29 August 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 September 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 September 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 November 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no relevant financial or non-financial interests to disclose.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of interest"}}]}}