{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:06:08Z","timestamp":1763154368531,"version":"3.45.0"},"reference-count":49,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21A20466","62425205","62032005","62102089"],"award-info":[{"award-number":["U21A20466","62425205","62032005","62102089"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tdsc.2025.3600224","type":"journal-article","created":{"date-parts":[[2025,8,19]],"date-time":"2025-08-19T18:18:29Z","timestamp":1755627509000},"page":"7835-7848","source":"Crossref","is-referenced-by-count":0,"title":["GAMC: Generic and Anti-MDA Model Certification for Intellectual Property Protection in MLaaS"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4770-7084","authenticated-orcid":false,"given":"Xiaohan","family":"Hao","sequence":"first","affiliation":[{"name":"Artificial Intelligence Thrust, Information Hub, Hong Kong University of Science and Technology (Guangzhou), Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0101-8531","authenticated-orcid":false,"given":"Chao","family":"Lin","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, College of Software, Nanjing University of Aeronautics and Astronautics, Fuzhou, China"}]},{"given":"Xuan","family":"He","sequence":"additional","affiliation":[{"name":"Artificial Intelligence Thrust, Information Hub, Hong Kong University of Science and Technology (Guangzhou), Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0070-1707","authenticated-orcid":false,"given":"Xinyi","family":"Huang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, College of Software, Nanjing University of Aeronautics and Astronautics, Fuzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1355"},{"article-title":"Machine learning as a service\u2013what is it? Who are the big players?","year":"2021","author":"Grunitz","key":"ref2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3535588"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.3389\/fdata.2021.729663"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00785"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3198267"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3518061"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.34133\/research.0442"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW54120.2021.00010"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i9.21193"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3412841.3441970"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3323873.3325042"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i12.26750"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3265535"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3443650"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom50675.2020.00062"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6976"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103102"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612515"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"ref23","first-page":"1615","article-title":"Turning your weakness into a strength: Watermarking deep neural networks by backdooring","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Adi"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559355"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450000"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599291"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/icassp.2019.8682202"},{"article-title":"FedSOV: Federated model secure ownership verification with unforgeable signature","year":"2023","author":"Yang","key":"ref28"},{"key":"ref29","first-page":"2347","article-title":"Rethinking white-box watermarks on deep learning models under neural structural obfuscation","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Yan"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833747"},{"key":"ref31","first-page":"22619","article-title":"Passport-aware normalization for deep model protection","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00363"},{"key":"ref33","first-page":"4714","article-title":"Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Fan"},{"key":"ref34","first-page":"2075","article-title":"Scaling verifiable computation using efficient set accumulators","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Ozdemir"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-26948-7_20"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539104"},{"key":"ref37","first-page":"2494","article-title":"To tune or not to tune? In search of optimal configurations for data analytics","volume-title":"Proc. 26th ACM SIGKDD Int. Conf. Knowl. Discov. Data Mining","author":"Fekry"},{"article-title":"Proof systems for general statements about discrete logarithms","year":"1997","author":"Camenisch","key":"ref38"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109844"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467405"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"key":"ref43","first-page":"1937","article-title":"Entangled watermarks as a defense against model extraction","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Jia"},{"article-title":"BlackMarks: Blackbox multibit watermarking for deep neural networks","year":"2019","author":"Chen","key":"ref44"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref47","first-page":"52","article-title":"SoK: How robust is deep neural network image classification watermarking","volume-title":"Proc. IEEE Symp. Secur. Privacy","author":"Lukas"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"Goodfellow","key":"ref48"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1126\/science.aab3050"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11242243\/11129249.pdf?arnumber=11129249","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:01:08Z","timestamp":1763154068000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11129249\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":49,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3600224","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"type":"print","value":"1545-5971"},{"type":"electronic","value":"1941-0018"},{"type":"electronic","value":"2160-9209"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}