{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:09:22Z","timestamp":1777889362840,"version":"3.51.4"},"reference-count":46,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00226","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"2346-2355","source":"Crossref","is-referenced-by-count":0,"title":["Staining and Locking Computer Vision Models Without Retraining"],"prefix":"10.1109","author":[{"given":"Oliver J.","family":"Sutton","sequence":"first","affiliation":[{"name":"Synoptix Ltd. and King&#x0027;s College London"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qinghua","family":"Zhou","sequence":"additional","affiliation":[{"name":"King&#x0027;s College London"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"George","family":"Leete","sequence":"additional","affiliation":[{"name":"Synoptix Ltd."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander N.","family":"Gorban","sequence":"additional","affiliation":[{"name":"Central Univ. Moscow"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ivan Y.","family":"Tyukin","sequence":"additional","affiliation":[{"name":"King&#x0027;s College London and AI Center, Bol&#x0027;shoi Bul&#x0027;var 30, Moscow and ISP RAS Research Center for Trusted Artificial Intelligence"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1615","article-title":"Turning your weakness into a strength: watermarking deep neural networks by backdooring","volume-title":"Proceedings of the 27th USENIX Conference on Security Symposium","author":"Adi","year":"2018"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3505634"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3620665.3640366"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1017\/9781009701853.002"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.3389\/fdata.2021.729663"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.3233\/faia250931"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3323873.3325042"},{"key":"ref8","author":"Chen","year":"2019","journal-title":"BlackMarks: Blackbox multibit watermarking for deep neural networks"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00130"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01169"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"ref12","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","author":"Dosovitskiy","year":"2020","journal-title":"arXiv preprint"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177728174"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3088846"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00438"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3685507"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240862"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref19","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00140"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"key":"ref22","year":"2024","journal-title":"King\u2019s Computational Research, Engineering and Technology Environment (CREATE)"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.07.051"},{"key":"ref24","author":"Li","year":"2021","journal-title":"Benchmarking detection transfer learning with vision transformers"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73650-6_16"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359801"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref28","first-page":"6978","article-title":"Watermarking deep neural networks with greedy residuals","volume-title":"Proceedings of the 38th International Conference on Machine Learning","author":"Liu","year":"2021"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46448-0_2"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1214\/aop\/1176990746"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30140"},{"key":"ref34","article-title":"Unsupervised representation learning with deep convolutional generative adversarial networks","author":"Radford","year":"2015","journal-title":"arXiv preprint"},{"key":"ref35","author":"Refael","year":"2024","journal-title":"SLIP: Securing LLMs IP using weights decomposition"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref39","author":"Simonyan","year":"2015","journal-title":"Very deep convolutional networks for large-scale image recognition"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179382"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.52202\/079017-1642"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-43427-3_10"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207472"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1093\/imamat\/hxad027"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.2352\/ISSN.2470-1173.2020.4.MWSF-022"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11444030.pdf?arnumber=11444030","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:09:52Z","timestamp":1777612192000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11444030\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":46,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00226","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}