{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T10:43:20Z","timestamp":1785926600483,"version":"3.56.0"},"reference-count":49,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Australia","award":["ARC LP220100453"],"award-info":[{"award-number":["ARC LP220100453"]}]},{"name":"Australia","award":["ARC DP240100955"],"award-info":[{"award-number":["ARC DP240100955"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3615615","type":"journal-article","created":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T17:56:21Z","timestamp":1759168581000},"page":"1219-1231","source":"Crossref","is-referenced-by-count":3,"title":["SMS: Self-Supervised Model Seeding for Verification of Machine Unlearning"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7905-3126","authenticated-orcid":false,"given":"Weiqi","family":"Wang","sequence":"first","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2352-0485","authenticated-orcid":false,"given":"Chenhan","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8905-0941","authenticated-orcid":false,"given":"Zhiyi","family":"Tian","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4485-6743","authenticated-orcid":false,"given":"Shui","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2013.03.010"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00019"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.35"},{"key":"ref4","first-page":"18075","article-title":"Remember what you want to forget: Algorithms for machine unlearning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Sekhari","year":"2021"},{"key":"ref5","first-page":"10355","article-title":"DeltaGrad: Rapid retraining of machine learning models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wu","year":"2020"},{"key":"ref6","first-page":"16025","article-title":"Variational Bayesian unlearning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Nguyen","year":"2020"},{"key":"ref7","first-page":"4007","article-title":"On the necessity of auditable algorithmic definitions for machine unlearning","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Thudi","year":"2022"},{"key":"ref8","first-page":"814","article-title":"Black box variational inference","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Ranganath","year":"2014"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1080\/07350015.2019.1624293"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/532"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0072"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3328269"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00390"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616617"},{"key":"ref15","first-page":"3454","article-title":"Input-aware dynamic backdoor attack","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Nguyen","year":"2020"},{"key":"ref16","article-title":"Knowledge removal in sampling-based Bayesian inference","volume-title":"Proc. 10th Int. Conf. Learn. Representations","author":"Fu","year":"2022"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3517406"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/556"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3382321"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00248"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670398"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3422799"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0072"},{"key":"ref24","first-page":"12293","article-title":"What makes unlearning hard and what to do about it","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhao","year":"2024"},{"key":"ref25","first-page":"1957","article-title":"Towards unbounded machine unlearning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Kurmanji","year":"2023"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3542092"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484756"},{"key":"ref28","article-title":"Machine unlearning of features and labels","volume-title":"Proc. 31th Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Warnecke","year":"2024"},{"key":"ref29","first-page":"4714","article-title":"Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Fan","year":"2019"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00363"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2023.3250210"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2019.2901877"},{"issue":"10","key":"ref33","first-page":"18","article-title":"Hiding an image inside another image using variable-rate steganography","volume":"4","author":"Tamimi","year":"2013","journal-title":"Int. J. Adv. Comput. Sci. Appl. (IJACSA)"},{"key":"ref34","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"ref37","volume-title":"Deep Learning","author":"Goodfellow","year":"2016"},{"key":"ref38","first-page":"8792","article-title":"Generalized cross entropy loss for training deep neural networks with noisy labels","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang","year":"2018"},{"key":"ref39","first-page":"37","article-title":"Autoencoders, unsupervised learning, and deep architectures","volume-title":"Proc. ICML Workshop Unsupervised Transfer Learn.","author":"Baldi","year":"2012"},{"key":"ref40","first-page":"2391","article-title":"Adversarial variational bayes: Unifying variational autoencoders and generative adversarial networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Mescheder","year":"2017"},{"key":"ref41","first-page":"525","article-title":"Multi-task learning as multi-objective optimization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Sener","year":"2018"},{"key":"ref42","first-page":"12060","article-title":"Pareto multi-task learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Lin","year":"2019"},{"key":"ref43","article-title":"Auto-encoding variational bayes","volume-title":"Proc. 2nd Int. Conf. Learn. Representations","author":"Kingma","year":"2014"},{"key":"ref44","first-page":"3832","article-title":"Certified data removal from machine learning models","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Guo","year":"2020"},{"key":"ref45","first-page":"4095","article-title":"Efficient neural architecture search via parameters sharing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pham","year":"2018"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00741"},{"key":"ref47","first-page":"58717","article-title":"Verification of machine unlearning is fragile","volume-title":"Proc. 41st Int. Conf. Mach. Learn.","author":"Zhang","year":"2024"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2014.2371246"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00463"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11184497.pdf?arnumber=11184497","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T23:23:23Z","timestamp":1768951403000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11184497\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":49,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3615615","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}