{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T16:51:14Z","timestamp":1775580674691,"version":"3.50.1"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFB3105000"],"award-info":[{"award-number":["2022YFB3105000"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62171248"],"award-info":[{"award-number":["62171248"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202393"],"award-info":[{"award-number":["62202393"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["12141108"],"award-info":[{"award-number":["12141108"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017610","name":"Shenzhen Science and Technology Program","doi-asserted-by":"publisher","award":["JCYJ20220818101012025"],"award-info":[{"award-number":["JCYJ20220818101012025"]}],"id":[{"id":"10.13039\/501100017610","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100012542","name":"Sichuan Science and Technology Program","doi-asserted-by":"publisher","award":["2023NSFSC1394"],"award-info":[{"award-number":["2023NSFSC1394"]}],"id":[{"id":"10.13039\/100012542","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018919","name":"Peng Cheng Laboratory (PCNL) Key Project","doi-asserted-by":"publisher","award":["PCL2021A07"],"award-info":[{"award-number":["PCL2021A07"]}],"id":[{"id":"10.13039\/100018919","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010877","name":"Shenzhen Science and Technology Innovation Commission (Research Center for Computer Network","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100010877","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tifs.2023.3265535","type":"journal-article","created":{"date-parts":[[2023,4,7]],"date-time":"2023-04-07T17:27:41Z","timestamp":1680888461000},"page":"2318-2332","source":"Crossref","is-referenced-by-count":81,"title":["Black-Box Dataset Ownership Verification via Backdoor Watermarking"],"prefix":"10.1109","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2258-265X","authenticated-orcid":false,"given":"Yiming","family":"Li","sequence":"first","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-8060-4237","authenticated-orcid":false,"given":"Mingyan","family":"Zhu","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4083-729X","authenticated-orcid":false,"given":"Xue","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Information Science and Technology, Southwest Jiaotong University, Chengdu, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4260-1395","authenticated-orcid":false,"given":"Yong","family":"Jiang","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, China"}]},{"given":"Tao","family":"Wei","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8639-982X","authenticated-orcid":false,"given":"Shu-Tao","family":"Xia","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2833032"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036803"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1018"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2523941"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.01.052"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2985532"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2972159"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475518"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3141725"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3131258"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108331"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref18","first-page":"1","article-title":"WaNet\u2014Imperceptible warping-based backdoor\n                        attack","volume-title":"Proc. ICLR","author":"Nguyen"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3032352"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9414149"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3089080"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3182979"},{"key":"ref24","first-page":"1","article-title":"Revisiting the assumption of latent separability for\n                        backdoor defenses","volume-title":"Proc. ICLR","author":"Qi"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109512"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref27","first-page":"1","article-title":"Few-shot backdoor attacks on visual object\n                        tracking","volume-title":"Proc. ICLR","author":"Li"},{"key":"ref28","first-page":"18021","article-title":"Manipulating SGD with data ordering\n                        attacks","volume-title":"Proc. NeurIPS","author":"Shumailov"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_7"},{"key":"ref32","article-title":"Targeted backdoor attacks on deep learning systems\n                        using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref33","first-page":"1","article-title":"Backdoor attack in the physical\n                    world","volume-title":"Proc. ICLR Workshop","author":"Li"},{"key":"ref34","first-page":"1","article-title":"How to inject backdoors with better consistency:\n                        Logit anchoring on clean data","volume-title":"Proc.\n                        ICLR","author":"Zhang"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485837"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3114024"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413468"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3084827"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3152247"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.2978386"},{"key":"ref41","volume-title":"Introduction to Mathematical Statistics","author":"Hogg","year":"2005"},{"key":"ref42","article-title":"Learning multiple layers of features from tiny\n                        images","author":"Krizhevsky","year":"2009"},{"key":"ref43","first-page":"1","article-title":"Very deep convolutional networks for large-scale\n                        image recognition","volume-title":"Proc. ICLR","author":"Simonyan"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref45","first-page":"142","article-title":"Learning word vectors for sentiment\n                        analysis","volume-title":"Proc. ACL","author":"Maas"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-76298-0_52"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1181"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2941376"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783417"},{"key":"ref51","first-page":"1","article-title":"How powerful are graph neural\n                        networks?","volume-title":"Proc. ICLR","author":"Xu"},{"key":"ref52","first-page":"1","article-title":"Inductive representation learning on large\n                        graphs","volume-title":"Proc. NeurIPS","author":"Hamilton"},{"key":"ref53","first-page":"1523","article-title":"Graph backdoor","volume-title":"Proc. USENIX Security","author":"Xi"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref57","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on\n                        poisoned data","volume-title":"Proc. NeurIPS","author":"Li"},{"key":"ref58","first-page":"1","article-title":"BackdoorBox: A Python toolbox for backdoor\n                        learning","volume-title":"Proc. ICLR Workshop","author":"Li"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20036"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3064850"},{"key":"ref61","first-page":"1","article-title":"Deep neural network fingerprinting by conferrable\n                        adversarial examples","volume-title":"Proc.\n                    ICLR","author":"Lukas"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3198267"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-95398-0_13"},{"key":"ref64","article-title":"Watermarking graph neural networks based on backdoor\n                        attacks","author":"Xu","year":"2021","journal-title":"arXiv:2110.11024"},{"key":"ref65","first-page":"1937","article-title":"Entangled watermarks as a defense against model\n                        extraction","volume-title":"Proc. USENIX\n                        Security","author":"Jia"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9970396\/10097580.pdf?arnumber=10097580","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,1]],"date-time":"2024-06-01T04:31:11Z","timestamp":1717216271000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10097580\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":65,"URL":"https:\/\/doi.org\/10.1109\/tifs.2023.3265535","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}