{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,8]],"date-time":"2026-02-08T04:54:24Z","timestamp":1770526464864,"version":"3.49.0"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Nanyang Technological University-Desay SV Research Program","award":["2018-0980"],"award-info":[{"award-number":["2018-0980"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tnnls.2025.3565170","type":"journal-article","created":{"date-parts":[[2025,5,19]],"date-time":"2025-05-19T13:57:53Z","timestamp":1747663073000},"page":"15939-15950","source":"Crossref","is-referenced-by-count":1,"title":["Persistence of Backdoor-Based Watermarks for Neural Networks: A Comprehensive Evaluation"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7224-6833","authenticated-orcid":false,"given":"Anh Tu","family":"Ngo","sequence":"first","affiliation":[{"name":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"}]},{"given":"Chuan Song","family":"Heng","sequence":"additional","affiliation":[{"name":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"}]},{"given":"Nandish","family":"Chattopadhyay","sequence":"additional","affiliation":[{"name":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8818-6983","authenticated-orcid":false,"given":"Anupam","family":"Chattopadhyay","sequence":"additional","affiliation":[{"name":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref2","first-page":"1877","article-title":"Language models are few-shot learners","volume-title":"Proc. NIPS","author":"Brown"},{"key":"ref3","article-title":"GPT-4 technical report","volume-title":"arXiv:2303.08774","author":"Achiam","year":"2024"},{"key":"ref4","article-title":"LaMDA: Language models for dialog applications","author":"Thoppilan","year":"2022","journal-title":"arXiv:2201.08239"},{"key":"ref5","article-title":"PaLM 2 technical report","volume-title":"arXiv:2305.10403","author":"Anil","year":"2023"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"ref8","first-page":"1615","article-title":"Turning your weakness into a strength: Watermarking deep neural networks by backdooring","volume-title":"Proc. 27th USENIX Conf. Security Symp.","author":"Adi"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3437880.3460401"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453079"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.07.051"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA52953.2021.00274"},{"key":"ref19","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref20","first-page":"1450","article-title":"Certified neural network watermarks with randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bansal"},{"key":"ref21","first-page":"28976","article-title":"Dimension-independent certified neural network watermarks via mollifier smoothing","volume-title":"Proc. 40th Int. Conf. Mach. Learn.","author":"Ren"},{"key":"ref22","first-page":"1937","article-title":"Entangled watermarks as a defense against model extraction","volume-title":"Proc. USENIX Secur. Symp.","author":"Jia"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00438"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612331"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i9.21184"},{"key":"ref26","first-page":"13238","article-title":"Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection","volume-title":"Proc. NIPS","author":"Li"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2023.3250210"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.2991378"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1609\/aaaiss.v4i1.31772"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/s0079-7421(08)60536-8"},{"key":"ref31","first-page":"2310","article-title":"Compete to compute","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"26","author":"Srivastava"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1611835114"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2013.2264952"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11651"},{"key":"ref35","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref36","article-title":"Reading digits in natural images with unsupervised feature learning","volume-title":"Proc. NIPS Workshop Deep Learn. Unsupervised Feature Learn.","author":"Netzer"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref38","first-page":"2017","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Dosovitskiy"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833693"},{"key":"ref40","first-page":"6389","article-title":"Visualizing the loss landscape of neural nets","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Li"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/5962385\/11151745\/11006759.pdf?arnumber=11006759","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T18:24:20Z","timestamp":1757096660000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11006759\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":40,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2025.3565170","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}