{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T03:00:13Z","timestamp":1781146813960,"version":"3.54.1"},"reference-count":34,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100002338","name":"Ministry of Education of the People's Republic of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100002338","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013139","name":"Humanities and Social Science Fund of Ministry of Education of the People's Republic of China","doi-asserted-by":"publisher","award":["25YJA880044"],"award-info":[{"award-number":["25YJA880044"]}],"id":[{"id":"10.13039\/501100013139","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.neunet.2026.109011","type":"journal-article","created":{"date-parts":[[2026,4,15]],"date-time":"2026-04-15T08:52:54Z","timestamp":1776243174000},"page":"109011","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["IRAW: Novel invisible and robust adversarial watermark perturbations for digital image protection"],"prefix":"10.1016","volume":"201","author":[{"given":"Jinchao","family":"Liang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yangcheng","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1222-1734","authenticated-orcid":false,"given":"Shuwu","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3427-9255","authenticated-orcid":false,"given":"Xiaolong","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.109011_bib0001","doi-asserted-by":"crossref","DOI":"10.1016\/1051-2004(91)90086-Z","article-title":"How I came up with the discrete cosine transform","author":"Ahmed","year":"1991","journal-title":"Digital Signal Processing"},{"issue":"9","key":"10.1016\/j.neunet.2026.109011_bib0002","first-page":"740","article-title":"Combined DWT-DCT digital image watermarking","volume":"3","author":"Alhaj","year":"2007","journal-title":"The Journal of Computer Science (New York, N.Y.)"},{"key":"10.1016\/j.neunet.2026.109011_bib0003","series-title":"Proceedings of the IEEE Symposium on Security and Privacy","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.neunet.2026.109011_bib0004","unstructured":"Das, N., Shanbhogue, M., Chen, S., Hohman, F., Chen, L., Kounavis, M. E., .& Chau, D. H. (.2017). Keeping the bad guys out: protecting and vaccinating deep learning with JPEG compression. https:\/\/doi.org\/10.48550\/arXiv.1705.02900, arXiv preprint arXiv:1705.02900."},{"key":"10.1016\/j.neunet.2026.109011_bib0005","doi-asserted-by":"crossref","DOI":"10.1016\/j.neucom.2024.127499","article-title":"Neural networks-based data hiding in digital images: Overview","volume":"581","author":"Dzhanashia","year":"2024","journal-title":"Neurocomputing"},{"key":"10.1016\/j.neunet.2026.109011_bib0006","unstructured":"Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., & Madry, A. (2017). Exploring the landscape of spatial robustness. https:\/\/doi.org\/10.48550\/arXiv.1712.02779, arXiv preprint arXiv:1712.02779."},{"key":"10.1016\/j.neunet.2026.109011_bib0007","doi-asserted-by":"crossref","unstructured":"Fawzi, A., & Frossard, P. (2015). Manitest: are classifiers really invariant. https:\/\/doi.org\/10.48550\/arXiv.1507.06535, arXiv preprint arXiv:1507.06535.","DOI":"10.5244\/C.29.106"},{"key":"10.1016\/j.neunet.2026.109011_bib0008","series-title":"Genetic algorithms in search, optimization, and machine learning","author":"Goldberg","year":"1989"},{"key":"10.1016\/j.neunet.2026.109011_bib0009","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. https:\/\/doi.org\/10.48550\/arXiv.1412.6572, arXiv preprint arXiv:1412.6572."},{"key":"10.1016\/j.neunet.2026.109011_bib0010","doi-asserted-by":"crossref","DOI":"10.25518\/0037-9565.6178","article-title":"A comparative study of image-in-image steganography using three methods of least significant bit, discrete wavelet transform and singular value decomposition","author":"Goli","year":"2016","journal-title":"Bulletin de la Soci\u00e9t\u00e9 Royale des Sciences de Li\u00e8ge"},{"key":"10.1016\/j.neunet.2026.109011_bib0011","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.neunet.2026.109011_bib0012","series-title":"Proceedings of the 28th ACM International Conference on Multimedia Retrieval","first-page":"1579","article-title":"Adv-watermark: A novel watermark perturbation for adversarial examples","author":"Jia","year":"2020"},{"key":"10.1016\/j.neunet.2026.109011_bib0013","series-title":"University of Toronto Technical Reports","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"10.1016\/j.neunet.2026.109011_bib0015","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"4441","article-title":"Geometric robustness of deep networks: Analysis and improvement","author":"Kanbak","year":"2018"},{"key":"10.1016\/j.neunet.2026.109011_bib0016","doi-asserted-by":"crossref","first-page":"6748","DOI":"10.1109\/ACCESS.2023.3236993","article-title":"Visual user-generated content verification in journalism: An overview","volume":"11","author":"Khan","year":"2023","journal-title":"IEEE access : practical innovations, open solutions"},{"key":"10.1016\/j.neunet.2026.109011_bib0017","doi-asserted-by":"crossref","first-page":"1489","DOI":"10.1007\/s11036-023-02158-y","article-title":"Enhancing security of medical images using deep learning, chaotic map, and hash table","volume":"29","author":"Kumar","year":"2024","journal-title":"Mobile Networks & Applications"},{"key":"10.1016\/j.neunet.2026.109011_bib0018","article-title":"BHI: embedded invisible watermark as adversarial example based on basin-hopping improvement","volume":"640","author":"Liang","year":"2023","journal-title":"Science (New York, N.Y.) Information"},{"issue":"1","key":"10.1016\/j.neunet.2026.109011_bib0019","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1007\/s10489-024-05917-w","article-title":"ISWP: novel high-fidelity adversarial examples generated by incorporating invisible and secure watermark perturbations","volume":"55","author":"Liang","year":"2025","journal-title":"Applied Intelligence"},{"key":"10.1016\/j.neunet.2026.109011_bib0020","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"2574","article-title":"DeepFool: A simple and accurate scheme to fool deep neural networks","author":"Moosavi-Dezfooli","year":"2016"},{"key":"10.1016\/j.neunet.2026.109011_bib0021","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"1765","article-title":"Universal adversarial perturbations","author":"Moosavi-Dezfooli","year":"2017"},{"key":"10.1016\/j.neunet.2026.109011_bib0022","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2024.109271","article-title":"Image watermarking based on a ratio of DCT coefficient sums using a gradient-based optimizer","volume":"117","author":"Melman","year":"2024","journal-title":"Computers & Electrical Engineering"},{"key":"10.1016\/j.neunet.2026.109011_bib0023","doi-asserted-by":"crossref","first-page":"110","DOI":"10.1201\/9781003427674-8","article-title":"Deep learning applications in digital image security","author":"Nawaz","year":"2023","journal-title":"Deep Learning for Multimedia Processing Applications"},{"key":"10.1016\/j.neunet.2026.109011_bib0024","series-title":"Proceedings of the IEEE Symposium on Security and Privacy","first-page":"582","article-title":"Distillation as a defense to adversarial perturbations against deep neural networks","author":"Papernot","year":"2016"},{"issue":"3","key":"10.1016\/j.neunet.2026.109011_bib0025","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","article-title":"ImageNet large scale visual recognition challenge","volume":"115","author":"Russakovsky","year":"2015","journal-title":"International The Journal of Computer Vision"},{"issue":"4","key":"10.1016\/j.neunet.2026.109011_bib0026","doi-asserted-by":"crossref","first-page":"341","DOI":"10.1023\/A:1008202821328","article-title":"Differential evolution \u2013 a simple and efficient heuristic for global optimization over continuous spaces","volume":"11","author":"Storn","year":"1997","journal-title":"The Journal of Global Optimization"},{"key":"10.1016\/j.neunet.2026.109011_bib0027","unstructured":"Simonyan, K., & Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. https:\/\/doi.org\/10.48550\/arXiv.1409.1556, arXiv preprint arXiv:1409.1556."},{"key":"10.1016\/j.neunet.2026.109011_bib0028","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"2818","article-title":"Rethinking the inception architecture for computer vision","author":"Szegedy","year":"2016"},{"key":"10.1016\/j.neunet.2026.109011_bib0029","unstructured":"Schott, L., Rauber, J., Bethge, M., & Brendel, W. (2018). Towards the first adversarially robust neural network model on MNIST. https:\/\/doi.org\/10.48550\/arXiv.1805.09190, arXiv preprint arXiv:1805.09190."},{"issue":"5","key":"10.1016\/j.neunet.2026.109011_bib0030","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One pixel attack for fooling deep neural networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Transactions on Evolutionary Computation"},{"issue":"18","key":"10.1016\/j.neunet.2026.109011_bib0031","doi-asserted-by":"crossref","first-page":"54027","DOI":"10.1007\/s11042-023-17559-0","article-title":"Watermarking approach for source authentication of web content in online social media: A systematic literature review","volume":"83","author":"Shaliyar","year":"2024","journal-title":"Multimedia Tools and Applications"},{"issue":"28","key":"10.1016\/j.neunet.2026.109011_bib0032","first-page":"5111","article-title":"Global optimization by basin-hopping and the lowest energy structures of Lennard-Jones clusters containing up to 110 atoms","volume":"101","author":"Wales","year":"1997","journal-title":"The Journal of Physical Chemistry (Weinheim an der Bergstrasse, Germany) A"},{"key":"10.1016\/j.neunet.2026.109011_bib0033","series-title":"Proceedings of the International Conference on Learning Representations","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Wieland","year":"2017"},{"key":"10.1016\/j.neunet.2026.109011_bib0035","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.121315","article-title":"Semi-fragile neural network watermarking for content authentication and tampering localization","volume":"236","author":"Yuan","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.neunet.2026.109011_bib0036","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"6848","article-title":"ShuffleNet: An extremely efficient convolutional neural network for mobile devices","author":"Zhang","year":"2018"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026004636?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026004636?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T02:53:15Z","timestamp":1781146395000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0893608026004636"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":34,"alternative-id":["S0893608026004636"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109011","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"IRAW: Novel invisible and robust adversarial watermark perturbations for digital image protection","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109011","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"109011"}}