{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,9,2]],"date-time":"2026-09-02T16:21:10Z","timestamp":1788366070354,"version":"build-2803163510"},"reference-count":34,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100013076","name":"National Major Science and Technology Projects of China","doi-asserted-by":"publisher","award":["2025ZD0123700-5"],"award-info":[{"award-number":["2025ZD0123700-5"]}],"id":[{"id":"10.13039\/501100013076","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62541604"],"award-info":[{"award-number":["62541604"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.jisa.2026.104561","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T03:19:22Z","timestamp":1782789562000},"page":"104561","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Federated learning ownership verification with fixed length watermarks using hash-based message authentication code"],"prefix":"10.1016","volume":"102","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0950-3897","authenticated-orcid":false,"given":"Suxia","family":"Zhu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jie","family":"Lou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guanglu","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.jisa.2026.104561_bib0001","first-page":"9","article-title":"Privacy and security issues in deep learning: a survey","author":"Liu","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104561_bib0002","doi-asserted-by":"crossref","first-page":"619","DOI":"10.1016\/j.future.2020.10.007","article-title":"A survey on security and privacy of federated learning","volume":"115","author":"Mothukuri","year":"2021","journal-title":"Future Gener Comput Syst"},{"key":"10.1016\/j.jisa.2026.104561_bib0003","unstructured":"H. Brendan Mcmahan et al. Communication-efficient learning of deep networks from decentralized data, in International Conference on Artificial Intelligence and Statistics, pages unknown, 2017."},{"issue":"4","key":"10.1016\/j.jisa.2026.104561_bib0004","doi-asserted-by":"crossref","first-page":"1382","DOI":"10.3390\/make5040070","article-title":"When federated learning meets watermarking: a comprehensive overview of techniques for intellectual property protection","volume":"5","author":"Lansari","year":"2023","journal-title":"Mach Learn Knowl Extr"},{"key":"10.1016\/j.jisa.2026.104561_bib0005","unstructured":"F. Boenisch, A survey on model watermarking neural networks, CoRR, Article abs\/2009.12153, 2020."},{"key":"10.1016\/j.jisa.2026.104561_bib0006","unstructured":"S. Waiwitlikhit et al. Trustless audits without revealing data or models, Comput Res Repository, arXiv:abs\/2404.04500, 2024."},{"key":"10.1016\/j.jisa.2026.104561_bib0007","unstructured":"Heng J. et al. ProFLingo: a fingerprinting-based copyright protection scheme for large language models, CoRR, abs\/2405.02466, 2024."},{"issue":"4","key":"10.1016\/j.jisa.2026.104561_bib0008","first-page":"4521","article-title":"FedIPR: ownership verification for federated deep neural network models","volume":"45","author":"Fan","year":"2021","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"10.1016\/j.jisa.2026.104561_bib0009","unstructured":"S. Shao et al. FedTracker: furnishing ownership verification and traceability for federated learning model, arXiv (Cornell University), 2022."},{"issue":"11","key":"10.1016\/j.jisa.2026.104561_bib0010","doi-asserted-by":"crossref","first-page":"15961","DOI":"10.1007\/s11042-022-12566-z","article-title":"Copyright protection of deep neural network models using digital watermarking: a comparative study","volume":"81","author":"Fkirin","year":"2022","journal-title":"Multimed Tools Appl"},{"key":"10.1016\/j.jisa.2026.104561_bib0011","author":"Song"},{"key":"10.1016\/j.jisa.2026.104561_bib0012","unstructured":"Y. Uchida et al. Embedding watermarks into deep neural networks. Comput Res Repos, abs\/1701.04082, 2017."},{"issue":"32","key":"10.1016\/j.jisa.2026.104561_bib0013","first-page":"4716","article-title":"Rethinking deep neural network ownership verification: embedding passports to defeat ambiguity attacks","volume":"32","author":"Fan","year":"2019","journal-title":"Adv Neural Inf Process Syst"},{"key":"10.1016\/j.jisa.2026.104561_bib0014","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"12805","article-title":"Model watermarking for image processing networks","volume":"34","author":"Zhang","year":"2020"},{"key":"10.1016\/j.jisa.2026.104561_bib0015","series-title":"ACM International Conference on Multimedia","first-page":"1579","article-title":"Adv-watermark: a novel watermark perturbation for adversarial examples","author":"Jia","year":"2020"},{"issue":"8","key":"10.1016\/j.jisa.2026.104561_bib0016","first-page":"4005","article-title":"Deep model intellectual property protection via deep watermarking","volume":"44","author":"Zhang","year":"2022","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"10.1016\/j.jisa.2026.104561_bib0017","doi-asserted-by":"crossref","unstructured":"E. Rodriguez-Lois, F. Perez-Gonzalez. Towards traitor tracing in black-and-white-box DNN watermarking with tardos-based codes. In 2023 IEEE International Workshop on Information Forensics and Security (WIFS), abs\/2307.06695, 2023.","DOI":"10.1109\/WIFS58808.2023.10374879"},{"key":"10.1016\/j.jisa.2026.104561_bib0018","unstructured":"C. Gu et al. Watermarking pre-trained language models with backdooring. arXiv (Cornell University), 2023."},{"key":"10.1016\/j.jisa.2026.104561_bib0019","unstructured":"Wang, Y. et al. SSCL-BW: sample-specific clean-label backdoor watermarking for dataset ownership verification, arXiv preprint arXiv2510.26420, 2025."},{"key":"10.1016\/j.jisa.2026.104561_bib0020","unstructured":"Li, J., and Y. Shen. Robust GNN watermarking via implicit perception of topological invariants, arXiv preprint arXiv2510.25934, 2025."},{"key":"10.1016\/j.jisa.2026.104561_bib0021","unstructured":"Ganesan, G. Cross-lingual summarization as a black-box watermark removal attack, arXiv preprint arXiv2510.24789, 2025."},{"key":"10.1016\/j.jisa.2026.104561_bib0022","doi-asserted-by":"crossref","unstructured":"B.G. Atli et al. WAFFLE: watermarking in federated learning. In IEEE International Symposium on Reliable Distributed Systems, 2021: 310\u201320.","DOI":"10.1109\/SRDS53918.2021.00038"},{"key":"10.1016\/j.jisa.2026.104561_bib0023","unstructured":"F.-Q. Li and S.-L. Wang. Towards practical watermark for deep neural networks in federated learning. arXiv (Cornell University), abs\/2105.03167, 2021."},{"issue":"1","key":"10.1016\/j.jisa.2026.104561_bib0024","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3630636","article-title":"Watermarking in secure federated learning: a verification framework based on client-side backdooring","volume":"15","author":"Yang","year":"2024","journal-title":"ACM Trans Intell Syst Technol"},{"key":"10.1016\/j.jisa.2026.104561_bib0025","unstructured":"J. Liang and R. Wang. FedCIP: federated client intellectual property protection with traitor tracking. CoRR, vol. abs\/2306.01356, 2023."},{"key":"10.1016\/j.jisa.2026.104561_bib0026","first-page":"135","article-title":"FedRight: an effective model copyright protection for federated learning","author":"Chen","year":"2023","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104561_bib0027","unstructured":"Y. Li et al. VeryFL: a verify federated learning framework embedded with blockchain. CoRR, vol. abs\/2311.15617, 2023."},{"key":"10.1016\/j.jisa.2026.104561_bib0028","unstructured":"Li, W. et al. Coward: toward practical proactive federated backdoor defense via collision-based watermark, arXiv preprint arXiv2508.02115, 2025."},{"key":"10.1016\/j.jisa.2026.104561_bib0029","doi-asserted-by":"crossref","unstructured":"He, P., and J. Joshi. PPFL-RDSN: privacy-preserving federated learning-based residual dense spatial networks for encrypted lossy image reconstruction, alphaxiv, 2025.","DOI":"10.1109\/TPS-ISA67132.2025.00013"},{"key":"10.1016\/j.jisa.2026.104561_bib0030","unstructured":"Xu, J. et al. Traceable black-box watermarks for federated learning, alphaxiv 2025."},{"key":"10.1016\/j.jisa.2026.104561_bib0031","doi-asserted-by":"crossref","unstructured":"Z. Gao et al. Fragile model watermark for integrity protection: leveraging boundary volatility and sensitive sample-pairing. CoRR, vol. abs\/2404.07572, 2024.","DOI":"10.1109\/ICME57554.2024.10688355"},{"key":"10.1016\/j.jisa.2026.104561_bib0032","series-title":"IEEE Symposium on Security and Privacy","first-page":"787","article-title":"SoK: how robust is image classification deep neural network watermarking?","author":"Lukas","year":"2022"},{"key":"10.1016\/j.jisa.2026.104561_bib0033","first-page":"80980.0","article-title":"Analysis and implementation of message authentication code (MAC) algorithms for GOOSE message security","volume":"7","author":"Suhail Hussain","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104561_bib0034","unstructured":"Yang, W. et al. FedSOV: federated model secure ownership verification with unforgeable signature, CoRR abs\/2305.06085, 2023."}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001912?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001912?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,9,2]],"date-time":"2026-09-02T16:00:30Z","timestamp":1788364830000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212626001912"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":34,"alternative-id":["S2214212626001912"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104561","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Federated learning ownership verification with fixed length watermarks using hash-based message authentication code","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104561","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104561"}}