{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T15:56:15Z","timestamp":1780502175367,"version":"3.54.1"},"reference-count":51,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2020YFB1805501"],"award-info":[{"award-number":["2020YFB1805501"]}]},{"name":"National Key Research and Development Program of China","award":["2018AAA0101100"],"award-info":[{"award-number":["2018AAA0101100"]}]},{"name":"National Key Research and Development Program of China","award":["2020YFB1806700"],"award-info":[{"award-number":["2020YFB1806700"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61932014"],"award-info":[{"award-number":["61932014"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Research and Development Program of Jiangsu, China","award":["BE2020026"],"award-info":[{"award-number":["BE2020026"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2023,4,1]]},"DOI":"10.1109\/tpami.2022.3195956","type":"journal-article","created":{"date-parts":[[2022,8,2]],"date-time":"2022-08-02T21:57:38Z","timestamp":1659477458000},"page":"4521-4536","source":"Crossref","is-referenced-by-count":90,"title":["FedIPR: Ownership Verification for Federated Deep Neural Network Models"],"prefix":"10.1109","volume":"45","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1602-3541","authenticated-orcid":false,"given":"Bowen","family":"Li","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lixin","family":"Fan","sequence":"additional","affiliation":[{"name":"WeBank, WeBank AI Lab, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hanlin","family":"Gu","sequence":"additional","affiliation":[{"name":"WeBank, WeBank AI Lab, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4974-6116","authenticated-orcid":false,"given":"Jie","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5059-8360","authenticated-orcid":false,"given":"Qiang","family":"Yang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Hong Kong University of Science and Technology, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.80"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.21437\/interspeech.2014-564"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.11"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/tpami.2021.3088846"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00363"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3064850"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108285"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"ref10","article-title":"DeepMarks: A Digital Fingerprinting Framework for Deep Neural Networks","author":"Chen","year":"2018"},{"key":"ref11","article-title":"DeepSigns: A Generic Watermarking Framework for IP Protection of Deep Learning Models","author":"Darvish Rouhani","year":"2018"},{"key":"ref12","first-page":"1615","article-title":"Turning your weakness into a strength: Watermarking deep neural networks by backdooring","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Adi"},{"key":"ref13","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref15","article-title":"Advances and open problems in federated learning","volume-title":"Found. Trends\u00ae Mach. Learn.","author":"Kairouz","year":"2019"},{"key":"ref16","first-page":"14 747","article-title":"Deep leakage from gradients","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Zhu"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref20","article-title":"ARIANN: low-interaction privacy-preserving deep learning via function secret sharing","volume-title":"CoRR","author":"Ryffel","year":"2020"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3563219"},{"key":"ref22","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. 31st Int. Conf. Neural Informat. Process. Syst.","author":"Blanchard"},{"key":"ref23","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in byzantium","volume-title":"Proc. Int. Conf. MachineMach. Learn.","author":"Guerraoui"},{"key":"ref24","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref25","first-page":"1846","article-title":"Free-rider attacks on model aggregation in federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Fraboni"},{"key":"ref26","article-title":"Free-riders in federated learning: Attacks and defenses","author":"Lin","year":"2019"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"ref28","article-title":"A survey on model watermarking neural networks","author":"Boenisch","year":"2020"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"ref34","article-title":"Deep neural network fingerprinting by conferrable adversarial examples","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Lukas"},{"key":"ref35","first-page":"22 619","article-title":"Passport-aware normalization for deep model protection","volume-title":"Proc. Adv. Neural Informat. Process. Syst.","author":"Zhang"},{"key":"ref36","first-page":"4714","article-title":"Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks","volume-title":"Proc. Adv. Neural Informat. Process. Syst.","author":"Fan"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2929409"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-020-02664-x"},{"key":"ref39","article-title":"Waffle: Watermarking in federated learning","author":"Atli","year":"2020"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SMC52423.2021.9658998"},{"key":"ref41","article-title":"Can You Really Backdoor Federated Learning?","author":"Sun","year":"2019"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref43","article-title":"How to backdoor federated learning","author":"Bagdasaryan","year":"2018"},{"key":"ref44","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref46","article-title":"Distilbert, a distilled version of bert: Smaller, faster, cheaper and lighter","author":"Sanh","year":"2019"},{"key":"ref47","first-page":"19","article-title":"Oort: Efficient federated learning via guided participant selection","volume-title":"Proc. 15th {USENIX} Symp. Operating Syst. Des. Implementation","author":"Lai"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref49","first-page":"242","article-title":"A convergence theory for deep learning via over-parameterization","author":"Allen-Zhu","year":"2019","journal-title":"Proc. Int. Conf. Mach. Learn."},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3446776"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/icde53745.2022.00077"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1016\/0097-3165(86)90026-9"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/10061515\/09847383.pdf?arnumber=9847383","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,25]],"date-time":"2024-06-25T19:52:18Z","timestamp":1719345138000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9847383\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,1]]},"references-count":51,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2022.3195956","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,1]]}}}