{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,11]],"date-time":"2025-11-11T13:24:14Z","timestamp":1762867454641,"version":"3.37.3"},"reference-count":29,"publisher":"Cambridge University Press (CUP)","issue":"2","license":[{"start":{"date-parts":[[2018,5,15]],"date-time":"2018-05-15T00:00:00Z","timestamp":1526342400000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/www.cambridge.org\/core\/terms"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Math. Struct. Comp. Sci."],"published-print":{"date-parts":[[2019,2]]},"abstract":"<jats:p>Software watermarking is a software protection technique used to defend the intellectual property of proprietary code. In particular, software watermarking aims at preventing software piracy by embedding a signature, i.e. an identifier reliably representing the owner, in the code. When an illegal copy is made, the owner can claim his\/her identity by extracting the signature. It is important to hide the signature in the program in order to make it difficult for the attacker to detect, tamper or remove it. In this work, we present a formal framework for software watermarking, based on program semantics and abstract interpretation, where attackers are modelled as abstract interpreters. In this setting, we can prove that the ability to identify signatures can be modelled as a completeness property of the attackers in the abstract interpretation framework. Indeed, hiding a signature in the code corresponds to embed it as a semantic property that can be retrieved only by attackers that are complete for it. Any abstract interpreter that is not complete for the property specifying the signature cannot detect, tamper or remove it. We formalize in the proposed framework the major quality features of a software watermarking technique: secrecy, resilience, transparence and accuracy. This provides a unifying framework for interpreting both watermarking schemes and attacks, and it allows us to formally compare the quality of different watermarking techniques. Indeed, a large number of watermarking techniques exist in the literature and they are typically evaluated with respect to their secrecy, resilience, transparence and accuracy to attacks. Formally identifying the attacks for which a watermarking scheme is secret, resilient, transparent or accurate can be a complex and error-prone task, since attacks and watermarking schemes are typically defined in different settings and using different languages (e.g. program transformation vs. program analysis), complicating the task of comparing one against the others.<\/jats:p>","DOI":"10.1017\/s0960129518000038","type":"journal-article","created":{"date-parts":[[2018,5,15]],"date-time":"2018-05-15T04:46:03Z","timestamp":1526359563000},"page":"339-388","source":"Crossref","is-referenced-by-count":5,"title":["Semantics-based software watermarking by abstract interpretation"],"prefix":"10.1017","volume":"29","author":[{"given":"MILA","family":"DALLA PREDA","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9475-4836","authenticated-orcid":false,"given":"MICHELE","family":"PASQUA","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"56","published-online":{"date-parts":[[2018,5,15]]},"reference":[{"key":"S0960129518000038_ref28","first-page":"177","article-title":"A functional taxonomy for software watermarking","volume":"24","author":"Nagra","year":"2002","journal-title":"Australian Computer Science Communications"},{"key":"S0960129518000038_ref26","unstructured":"Mastroeni I. (2005). Abstract Non-Interference - An Abstract Interpretation-based Approach to Secure Information Flow; PhD thesis; University of Verona \u2013 Dep. of Computer Science; Strada le Grazie 15, 37134, Verona (Italy)."},{"key":"S0960129518000038_ref22","unstructured":"Giacobazzi R. and Mastroeni I. (2004). Abstract non-interference: Parameterizing non-interference by abstract interpretation. In: Proceedings of the 31st Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages (POPL'04), ACM-Press 186\u2013197."},{"key":"S0960129518000038_ref21","doi-asserted-by":"crossref","unstructured":"Giacobazzi R. and Mastroeni I. (2002). Compositionality in the puzzle of semantics. In: Proceedings of the 2002 ACM SIGPLAN Workshop on Partial Evaluation and Semantics-Based Program Manipulation (PEPM '02), Portland, Oregon, USA, January 14\u201315 87\u201397.","DOI":"10.1145\/503032.503040"},{"key":"S0960129518000038_ref20","doi-asserted-by":"crossref","unstructured":"Giacobazzi R. (2008). Hiding information in completeness holes \u2013 new perspectives in code obfuscation and watermarking. In: Proceedings of The 6th IEEE International Conferences on Software Engineering and Formal Methods (SEFM'08), IEEE Press. 7\u201320.","DOI":"10.1109\/SEFM.2008.41"},{"key":"S0960129518000038_ref19","doi-asserted-by":"crossref","unstructured":"Garg S. , Gentry C. , Halevi S. , Raykova M. , Sahai A. and Waters B. (2013). Candidate indistinguishability obfuscation and functional encryption for all circuits. In: IACR Cryptology ePrint Archive, 451.","DOI":"10.1109\/FOCS.2013.13"},{"key":"S0960129518000038_ref18","unstructured":"Frontier-Economics (2016). The economic impacts of counterfeiting and piracy \u2013 report prepared for bascap and inta. online. Available at: https:\/\/iccwbo.org\/publication\/economic-impacts-counterfeiting-piracy-report-prepared-bascap-inta\/."},{"key":"S0960129518000038_ref14","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2009-0345"},{"key":"S0960129518000038_ref13","doi-asserted-by":"crossref","unstructured":"Dalla Preda M. and Giacobazzi R. (2005). Semantic-based code obfuscation by abstract interpretation. In: Proceeding of the 32nd International Colloquium on Automata, Languages and Programming (ICALP'05), Lecture Notes in Computer Science, vol. 3580, Springer-Verlag 1325\u20131336.","DOI":"10.1007\/11523468_107"},{"key":"S0960129518000038_ref12","doi-asserted-by":"crossref","unstructured":"Cousot P. and Cousot R. (2004). An abstract interpretation-based framework for software watermarking. In: Conference Record of the 31st Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, ACM Press, New York, NY, USA 173\u2013185.","DOI":"10.1145\/964001.964016"},{"key":"S0960129518000038_ref9","doi-asserted-by":"crossref","unstructured":"Cousot P. and Cousot R. (1977). Abstract interpretation: A unified lattice model for static analysis of programs by construction or approximation of fixpoints. In: Conference Record of the 4th ACM Symposium on Principles of Programming Languages (POPL'77), ACM Press 238\u2013252.","DOI":"10.1145\/512950.512973"},{"key":"S0960129518000038_ref8","doi-asserted-by":"publisher","DOI":"10.1016\/S0304-3975(00)00313-3"},{"key":"#cr-split#-S0960129518000038_ref15.2","unstructured":"11., Valencia, Spain, July 16-18, 2008, Lecture Notes in Computer Science, vol. 5079 174-188."},{"key":"S0960129518000038_ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2017.02.005"},{"key":"S0960129518000038_ref10","doi-asserted-by":"crossref","unstructured":"Cousot P. and Cousot R. (1979). Systematic design of program analysis frameworks. In: Conference Record of the 6th ACM Symposium on Principles of Programming Languages (POPL'79), ACM Press 269\u2013282.","DOI":"10.1145\/567752.567778"},{"key":"S0960129518000038_ref11","doi-asserted-by":"crossref","unstructured":"Cousot P. and Cousot R. (2002). Systematic design of program transformation frameworks by abstract interpretation. In: Conference Record of the 29th Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, ACM Press 178\u2013190.","DOI":"10.1145\/503272.503290"},{"key":"S0960129518000038_ref27","unstructured":"Moskowitz S.A. and Cooperman M. (1996). Method for stega-cipher protection of computer code; US patent 5.745.569; Assignee: The Dice Company."},{"key":"S0960129518000038_ref17","unstructured":"Davidson R.L. and Myhrvold N. (1996). Method and system for generating and auditing a signature for a computer program. US Patent number 5,559,884."},{"key":"S0960129518000038_ref29","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45496-9_12"},{"key":"S0960129518000038_ref24","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-47764-0_20"},{"key":"S0960129518000038_ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2002.1027797"},{"key":"S0960129518000038_ref3","doi-asserted-by":"publisher","DOI":"10.1145\/996893.996856"},{"key":"S0960129518000038_ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-69166-2_1"},{"key":"S0960129518000038_ref2","unstructured":"BSA (2016). Global Software Survey: Seizing Opportunity Through License Compliance, Online. Available at http:\/\/globalstudy.bsa.org\/2016\/."},{"key":"S0960129518000038_ref25","doi-asserted-by":"publisher","DOI":"10.1145\/333979.333989"},{"key":"S0960129518000038_ref6","unstructured":"Collberg C. , Thomborson C.D. and Low D. (1997). A taxonomy of obfuscating transformations; Technical Report 148; Department of Computer Science, The University of Auckland."},{"key":"S0960129518000038_ref7","unstructured":"Collberg C. , Thomborson C.D. and Low D. (1998). Manufactoring cheap, resilient, and stealthy opaque constructs. In: Proceedings of Conference Record of the 25st ACM Symp osium on Principles of Programming Languages (POPL'98), ACM Press 184\u2013196."},{"key":"S0960129518000038_ref1","unstructured":"Barak B. , Goldreich O. , Impagliazzo R. , Rudich S. , Sahai A. , Vadhan S.P. and Yang K. (2001). On the (im)possibility of obfuscating programs. In: CRYPTO '01: Proceedings of the 21st Annual International Cryptology Conference on Advances in Cryptology, Springer-Verlag 1\u201318."},{"key":"S0960129518000038_ref5","unstructured":"Collberg C. and Thomborson C.D. (1999). Software watermarking: Models and dynamic embeddings. In: POPL '99: Proceedings of the 26th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, ACM 311\u2013324."}],"container-title":["Mathematical Structures in Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.cambridge.org\/core\/services\/aop-cambridge-core\/content\/view\/S0960129518000038","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,4,12]],"date-time":"2019-04-12T15:32:12Z","timestamp":1555083132000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.cambridge.org\/core\/product\/identifier\/S0960129518000038\/type\/journal_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,5,15]]},"references-count":29,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2019,2]]}},"alternative-id":["S0960129518000038"],"URL":"https:\/\/doi.org\/10.1017\/s0960129518000038","relation":{},"ISSN":["0960-1295","1469-8072"],"issn-type":[{"type":"print","value":"0960-1295"},{"type":"electronic","value":"1469-8072"}],"subject":[],"published":{"date-parts":[[2018,5,15]]}}}