{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T11:23:40Z","timestamp":1779103420222,"version":"3.51.4"},"reference-count":94,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Nature Science Foundation of China","doi-asserted-by":"publisher","award":["62425114,62121002,U23B2028,62232006,62472395"],"award-info":[{"award-number":["62425114,62121002,U23B2028,62232006,62472395"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00233","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"2417-2428","source":"Crossref","is-referenced-by-count":1,"title":["Invisible Watermarks, Visible Gains: Steering Machine Unlearning with Bi-Level Watermarking Design"],"prefix":"10.1109","author":[{"given":"Yuhao","family":"Sun","sequence":"first","affiliation":[{"name":"University of Science and Technology of China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yihua","family":"Zhang","sequence":"additional","affiliation":[{"name":"Michigan State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gaowen","family":"Liu","sequence":"additional","affiliation":[{"name":"Cisco Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongtao","family":"Xie","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sijia","family":"Liu","sequence":"additional","affiliation":[{"name":"Michigan State University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00019"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3749987"},{"key":"ref3","article-title":"Are we making progress in unlearning? findings from the first neurips unlearning competition","author":"Triantafillou","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-025-00985-0"},{"key":"ref5","article-title":"The right to delete","volume-title":"2010 AAAI Spring Symposium Series","author":"Conley","year":"2010"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.35"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.32604\/cmc.2023.032307"},{"key":"ref8","article-title":"Avoiding copyright infringement via machine unlearning","author":"Dou","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref9","article-title":"Unlearncanvas: A stylized image dataset to benchmark machine unlearning for diffusion models","author":"Zhang","year":"2024","journal-title":"NeurIPS"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00352"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2246"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796974"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CNS62487.2024.10735680"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.107"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"ref16","article-title":"Defensive unlearning with adversarial training for robust concept erasure in diffusion models","author":"Zhang","year":"2024","journal-title":"NeurIPS"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TETCI.2024.3379240"},{"key":"ref18","article-title":"Machine unlearning in generative ai: A survey","author":"Liu","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref19","first-page":"2008","article-title":"Approximate data deletion from machine learning models","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Izzo","year":"2021"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00932"},{"key":"ref21","article-title":"Evaluating machine unlearning via epistemic uncertainty","author":"Becker","year":"2022","journal-title":"arXiv preprint arXiv"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00027"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23087"},{"key":"ref24","article-title":"Towards unbounded machine unlearning","volume":"36","author":"Kurmanji","year":"2024","journal-title":"Advances in neural information processing systems"},{"key":"ref25","article-title":"Salun: Empowering machine unlearning via gradient-based weight saliency in both image classification and generation","author":"Fan","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICICTA.2010.625"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01137"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2024.100662"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(02)00122-X"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2016.2627241"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01267-0_40"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01356"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-023-15750-x"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.3390\/app132111852"},{"key":"ref35","article-title":"Making ai forget you: Data deletion in machine learning","volume":"32","author":"Ginart","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref36","first-page":"931","article-title":"Descent-to-delete: Gradient-based methods for machine unlearning","volume-title":"Algorithmic Learning Theory","author":"Neel","year":"2021"},{"key":"ref37","first-page":"18075","article-title":"Remember what you want to forget: Algorithms for machine unlearning","volume":"34","author":"Sekhari","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref38","first-page":"4126","article-title":"Machine unlearning via algorithmic stability","volume-title":"Conference on Learning Theory","author":"Ullah","year":"2021"},{"key":"ref39","first-page":"4007","article-title":"On the necessity of auditable algorithmic definitions for machine unlearning","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Thudi","year":"2022"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i13.17371"},{"key":"ref42","article-title":"Certified data removal from machine learning models","author":"Guo","year":"2019","journal-title":"arXiv preprint arXiv"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00503"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0751"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.02074"},{"key":"ref46","article-title":"Forget-me-not: Learning to forget in text-toimage diffusion models","author":"Zhang","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref47","volume-title":"Fast federated machine unlearning with nonlinear functional theory","author":"Che","year":"2023"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512222"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.001.2200198"},{"key":"ref50","volume-title":"Who\u2019s harry potter? approximate unlearning in large language models","author":"Eldan","year":"2023"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.174"},{"key":"ref52","article-title":"Large language model unlearning","author":"Yao","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.375"},{"key":"ref54","volume-title":"Digital watermarking and steganography","author":"Cox","year":"2007"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2000.899260"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/35.940053"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.1997.647964"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/S0165-1684(98)00015-2"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.1997.647971"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/6046.985560"},{"key":"ref61","article-title":"Steganogan: High capacity image steganography with gans","author":"Zhang","year":"2019","journal-title":"arXiv preprint arXiv"},{"key":"ref62","article-title":"Are watermarks bugs for deepfake detectors? rethinking proactive forensics","author":"Wu","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref63","article-title":"Hide and seek: How does watermarking impact face recognition?","author":"Yao","year":"2024","journal-title":"arXiv preprint arXiv"},{"issue":"3","key":"ref64","first-page":"4","article-title":"Exploring visual prompts for adapting large-scale models","volume":"1","author":"Bahng","year":"2022","journal-title":"arXiv preprint arXiv"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19827-4_41"},{"key":"ref66","article-title":"Adversarial reprogramming of neural networks","author":"Elsayed","year":"2018","journal-title":"arXiv preprint arXiv"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1016\/b978-0-12-824020-5.00030-2"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/d19-1525"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/wacv51458.2022.00295"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3459637.3482053"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.52202\/068431-2489"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/icassp49357.2023.10097245"},{"key":"ref73","article-title":"Showmaker: Creating high-fidelity 2d human video via fine-grained diffusion modeling","volume-title":"NeurIPS","author":"Yang","year":"2024"},{"key":"ref74","article-title":"From visual prompt learning to zero-shot transfer: Mapping is all you need","author":"Yang","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref75","article-title":"Unleashing the power of visual prompting at the pixel level","author":"Wu","year":"2022","journal-title":"arXiv preprint arXiv"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10097245"},{"key":"ref77","article-title":"Understanding zero-shot adversarial robustness for large-scale models","author":"Mao","year":"2022","journal-title":"arXiv preprint arXiv"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00476"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i4.32431"},{"key":"ref80","article-title":"When visual prompt tuning meets source-free domain adaptive semantic segmentation","volume":"36","author":"Ma","year":"2024","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref81","volume-title":"Visual prompting reimagined: The power of activation prompts","author":"Zhang","year":"2024"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52729.2023.01047"},{"key":"ref83","article-title":"Self-supervised convolutional visual prompts","author":"Tsai","year":"2023","journal-title":"arXiv preprint arXiv"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-022-01653-1"},{"key":"ref85","article-title":"Visual prompting in multimodal large language models: A survey","author":"Wu","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i3.28064"},{"key":"ref87","article-title":"Attribute-to-delete: Machine unlearning via datamodel matching","author":"Georgiev","year":"2024","journal-title":"arXiv preprint arXiv"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00750"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2024.3358284"},{"key":"ref90","volume-title":"Tofu: A task of fictitious unlearning for llms","author":"Maini","year":"2024"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-5981-1"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3201490"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72664-4_16"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11449019.pdf?arnumber=11449019","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:33:44Z","timestamp":1777613624000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11449019\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":94,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00233","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}