{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T03:58:53Z","timestamp":1784001533484,"version":"3.55.0"},"reference-count":21,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T00:00:00Z","timestamp":1706745600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T00:00:00Z","timestamp":1706745600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["AI Ethics"],"published-print":{"date-parts":[[2024,2]]},"DOI":"10.1007\/s43681-023-00412-3","type":"journal-article","created":{"date-parts":[[2024,2,23]],"date-time":"2024-02-23T07:02:25Z","timestamp":1708671745000},"page":"95-103","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Protecting ownership rights of ML models using watermarking in the light of adversarial attacks"],"prefix":"10.1007","volume":"4","author":[{"given":"Katarzyna","family":"Kapusta","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lucas","family":"Mattioli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Boussad","family":"Addad","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammed","family":"Lansari","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,2,23]]},"reference":[{"key":"412_CR1","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., Mian, A.: Threat of adversarial attacks on deep learning in computer vision: A survey. Ieee Access 6, 14410\u201314430 (2018)","journal-title":"Ieee Access"},{"key":"412_CR2","doi-asserted-by":"crossref","unstructured":"Uchida, Y., Nagai, Y., Sakazawa, S., Satoh, S.: Embedding watermarks into deep neural networks. In Proceedings of the 2017 ACM on International Conference on Multimedia Retrieval. (2017)","DOI":"10.1145\/3078971.3078974"},{"key":"412_CR3","unstructured":"Fan, L., Ng, K.W., Chan, C.S.: Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks. Advances in neural information processing systems, 32. (2019)"},{"key":"412_CR4","unstructured":"Adi, Y., Baum, C., Cisse, M., Pinkas, B., Keshet, J.: Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX Security Symposium (USENIX Security 18). (2018)"},{"key":"412_CR5","doi-asserted-by":"crossref","unstructured":"Zhang, J., Gu, Z., Jang, J., Wu, H., Stoecklin, M.P., Huang, H., Molloy, I.: Protecting intellectual property of deep neural networks with watermarking. In Proceedings of the 2018 on Asia Conference on Computer and Communications Security. (2018)","DOI":"10.1145\/3196494.3196550"},{"key":"412_CR6","unstructured":"Kapusta, K., Thouvenot, V., Bettan, O.: Watermarking at the service of intellectualproperty rights of ML models. Conference on Artificial Intelligence for Defense (CAID). (2020)"},{"key":"412_CR7","doi-asserted-by":"crossref","unstructured":"Wang, T., Kerschbaum, F.: Attacks on digital watermarks for deep neural networks. IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). (2019)","DOI":"10.1109\/ICASSP.2019.8682202"},{"issue":"11","key":"412_CR8","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1145\/3422622","volume":"63","author":"I Goodfellow","year":"2020","unstructured":"Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., Bengio, Y.: Generative adversarial networks. Commun. ACM 63(11), 139\u2013144 (2020)","journal-title":"Commun. ACM"},{"key":"412_CR9","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., Fergus, R.: Intriguing properties of neural networks. arXiv preprintarXiv:1312.6199. (2013)"},{"key":"412_CR10","doi-asserted-by":"crossref","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndi\u0107, N., Laskov, P., Giacinto, G., Roli, F.: Evasion attacks against machine learning at test time. In Joint European conference on machine learning and knowledge discovery in databases. pp. 387\u2013402. Springer (2013)","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"412_CR11","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial Machine Learning at Scale. (2017)"},{"key":"412_CR12","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards Deep Learning Models Resistant to Adversarial Attacks. In 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings. (2018)"},{"key":"412_CR13","unstructured":"Cohen, J., Rosenfeld, E., Kolter, Z.: Certified adversarial robustness via randomized smoothing. In International Conference on Machine Learning. pp. 1310\u20131320. PMLR (2019)"},{"key":"412_CR14","doi-asserted-by":"crossref","unstructured":"Nguyen, A., Yosinski, J., Clune, J.: Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. In Proceedings of the IEEE conference on computer vision and pattern recognition. pp. 427\u2013436. (2015)","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"412_CR15","unstructured":"Brown, T.B., Man\u00e9, D., Roy, A., Abadi, M., Gilmer, J.: Adversarial patch. arXiv preprintarXiv:1712.09665. (2017)"},{"key":"412_CR16","unstructured":"Braunschweig, B., Gelin, R., Terrier, F.: The wall of safety for AI: approaches in the confiance. ai program. In Workshop on Artificial Intelligence Safety (SAFEAI). (2022)"},{"key":"412_CR17","unstructured":"Confiance.ai; et\u00a0al. Towards the engineering of trustworthy AI applications for critical systems\u2014The Confiance.ai program (2022)"},{"key":"412_CR18","doi-asserted-by":"crossref","unstructured":"Krause, J., Stark, M., Deng, J., Fei-Fei, L.: 3D Object Representations for Fine-Grained Categorization. In Proceedings of the IEEE International Conference on Computer Vision (ICCV) Workshops. (2013)","DOI":"10.1109\/ICCVW.2013.77"},{"key":"412_CR19","doi-asserted-by":"crossref","unstructured":"Li, Z., Hu, C., Zhang, Y., Guo, S.: How to Prove Your Model Belongs to You: A Blind-Watermark Based Framework to Protect Intellectual Property of DNN. In Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC \u201919, 126-137. New York, NY, USA: Association for Computing Machinery. ISBN 9781450376280. (2019)","DOI":"10.1145\/3359789.3359801"},{"key":"412_CR20","unstructured":"Lansari, M., Kapusta, K., Thouvenot, V.: How to efficiently and explicitly watermark your Convolutional Neural Network. In Conference on Artificial Intelligence for Defense, Actes de la 4\u00e8me Conference on Artificial Intelligence for Defense (CAID 2022). Rennes, France: DGA Ma\u00eetrise de l\u2019Information. (2022)"},{"key":"412_CR21","doi-asserted-by":"crossref","unstructured":"Kapusta, K., Thouvenot, V., Bettan, O., Beguinet, H., Senet, H.: A Protocol for Secure Verification of Watermarks Embedded into Machine Learning Models. In Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security, IH & MMSec \u201921. pp. 171-176. New York, NY, USA: Association for Computing Machinery. ISBN 9781450382953 (2021)","DOI":"10.1145\/3437880.3460409"}],"container-title":["AI and Ethics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s43681-023-00412-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s43681-023-00412-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s43681-023-00412-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T09:13:24Z","timestamp":1713172404000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s43681-023-00412-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2]]},"references-count":21,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,2]]}},"alternative-id":["412"],"URL":"https:\/\/doi.org\/10.1007\/s43681-023-00412-3","relation":{},"ISSN":["2730-5953","2730-5961"],"issn-type":[{"value":"2730-5953","type":"print"},{"value":"2730-5961","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,2]]},"assertion":[{"value":"23 February 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}