{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T16:45:55Z","timestamp":1783788355267,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,6,17]],"date-time":"2021-06-17T00:00:00Z","timestamp":1623888000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Agencia Estatal de Investigacion (Spain) and the European Regional Development Fund (ERDF)","award":["ED431G2019\/08"],"award-info":[{"award-number":["ED431G2019\/08"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,6,17]]},"DOI":"10.1145\/3437880.3460399","type":"proceedings-article","created":{"date-parts":[[2021,6,21]],"date-time":"2021-06-21T13:11:52Z","timestamp":1624281112000},"page":"189-196","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["DNN Watermarking: Four Challenges and a Funeral"],"prefix":"10.1145","author":[{"given":"Mauro","family":"Barni","sequence":"first","affiliation":[{"name":"University of Siena, Siena, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fernando","family":"P\u00e9rez-Gonz\u00e1lez","sequence":"additional","affiliation":[{"name":"University of Vigo, Vigo, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Benedetta","family":"Tondi","sequence":"additional","affiliation":[{"name":"University of Siena, Siena, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,6,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"M. Barni F. Bartolini A. De Rosa and A. Piva. 1999. Capacity of the watermark channel: How many bits can be hidden within a digital image?. In Security and Watermarking of Multimedia Contents. International Society for Optics and Photonics .  M. Barni F. Bartolini A. De Rosa and A. Piva. 1999. Capacity of the watermark channel: How many bits can be hidden within a digital image?. In Security and Watermarking of Multimedia Contents. International Society for Optics and Photonics .","DOI":"10.1117\/12.344694"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2005.855418"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/18.923725"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3323873.3325042"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2017.2721104"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"P. Comesa\n     na L.\n      P\u00e9rez-Freire and \n      F.\n      P\u00e9rez-Gonz\u00e1lez\n  . \n  2005\n  . Fundamentals of Data Hiding Security and Their Application to Spread-Spectrum Analysis. In Information Hiding. IB 2005 Lecture Notes in Computer Science Vol. \n  3727\n  . \n  Springer\n  . https:\/\/doi.org\/10.1007\/11558859_12    10.1007\/11558859_12\nP. Comesa na L. P\u00e9rez-Freire and F. P\u00e9rez-Gonz\u00e1lez. 2005. Fundamentals of Data Hiding Security and Their Application to Spread-Spectrum Analysis. In Information Hiding. IB 2005 Lecture Notes in Computer Science Vol. 3727. Springer. https:\/\/doi.org\/10.1007\/11558859_12","DOI":"10.1007\/11558859_12"},{"key":"e_1_3_2_1_7_1","volume-title":"Entropy","volume":"22","author":"Lorenzo Betty Corti","year":"2020","unstructured":"Betty Corti nas- Lorenzo and Fernando P\u00e9rez-Gonz\u00e1lez . 2020 . Adam and the Ants: On the Influence of the Optimization Algorithm on the Detectability of DNN Watermarks . Entropy , Vol. 22 , 12 (2020). https:\/\/doi.org\/10.3390\/e22121379 10.3390\/e22121379 Betty Corti nas-Lorenzo and Fernando P\u00e9rez-Gonz\u00e1lez. 2020. Adam and the Ants: On the Influence of the Optimization Algorithm on the Detectability of DNN Watermarks. Entropy , Vol. 22, 12 (2020). https:\/\/doi.org\/10.3390\/e22121379"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056659"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/83.650120"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2005.855591"},{"key":"e_1_3_2_1_11_1","unstructured":"U. Erez and R. Zamir. 2004. Achieving 1\/2 log (1  U. Erez and R. Zamir. 2004. Achieving 1\/2 log (1"},{"key":"e_1_3_2_1_12_1","volume-title":"IEEE Transactions on Information Theory","volume":"50","year":"2004","unstructured":"SNR) on the AWGN channel with lattice encoding and decoding . IEEE Transactions on Information Theory , Vol. 50 , 10 ( 2004 ), 2293--2314. https:\/\/doi.org\/10.1109\/TIT.2004.834787 10.1109\/TIT.2004.834787 SNR) on the AWGN channel with lattice encoding and decoding. IEEE Transactions on Information Theory , Vol. 50, 10 (2004), 2293--2314. https:\/\/doi.org\/10.1109\/TIT.2004.834787"},{"key":"e_1_3_2_1_13_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017). Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_1_14_1","volume-title":"Lossy Image Compression with Compressive Autoencoders. In International Conference on Learning Representations (ICLR 2017)","author":"Huszar F.","year":"1995","unstructured":"F. Huszar , L. Theis , W. Shi , and A. Cunningham . 2017 . Lossy Image Compression with Compressive Autoencoders. In International Conference on Learning Representations (ICLR 2017) . https:\/\/doi.org\/110.17863\/CAM.5 1995 F. Huszar, L. Theis, W. Shi, and A. Cunningham. 2017. Lossy Image Compression with Compressive Autoencoders. In International Conference on Learning Representations (ICLR 2017) . https:\/\/doi.org\/110.17863\/CAM.51995"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.771068"},{"key":"e_1_3_2_1_16_1","volume-title":"Lecture Notes in Computer Science","volume":"11218","author":"Kokkinos F.","unstructured":"F. Kokkinos and S. Lefkimmiatis . 2018. Deep Image Demosaicking Using a Cascade of Convolutional Residual Denoising Networks. In Computer Vision -- ECCV 2018 . Lecture Notes in Computer Science , Vol. 11218 . https:\/\/doi.org\/10.1007\/978--3-030-01264--9_19 10.1007\/978--3-030-01264--9_19 F. Kokkinos and S. Lefkimmiatis. 2018. Deep Image Demosaicking Using a Cascade of Convolutional Residual Denoising Networks. In Computer Vision -- ECCV 2018. Lecture Notes in Computer Science, Vol. 11218. https:\/\/doi.org\/10.1007\/978--3-030-01264--9_19"},{"key":"e_1_3_2_1_17_1","unstructured":"Yue Li Benedetta Tondi and Mauro Barni. 2020. Spread-Transform Dither Modulation Watermarking of Deep Neural Network. arxiv: cs.CR\/2012.14171  Yue Li Benedetta Tondi and Mauro Barni. 2020. Spread-Transform Dither Modulation Watermarking of Deep Neural Network. arxiv: cs.CR\/2012.14171"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_19_1","volume-title":"Pruning convolutional neural networks for resource efficient inference. arXiv preprint arXiv:1611.06440","author":"Molchanov Pavlo","year":"2016","unstructured":"Pavlo Molchanov , Stephen Tyree , Tero Karras , Timo Aila , and Jan Kautz . 2016. Pruning convolutional neural networks for resource efficient inference. arXiv preprint arXiv:1611.06440 ( 2016 ). Pavlo Molchanov, Stephen Tyree, Tero Karras, Timo Aila, and Jan Kautz. 2016. Pruning convolutional neural networks for resource efficient inference. arXiv preprint arXiv:1611.06440 (2016)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13735-018-0147-1"},{"key":"e_1_3_2_1_21_1","volume-title":"Deep Multi-scale Convolutional Neural Network for Dynamic Scene Deblurring. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) . 257--265","author":"Nah S.","year":"2017","unstructured":"S. Nah , T. H. Kim , and K. M. Lee . 2017 . Deep Multi-scale Convolutional Neural Network for Dynamic Scene Deblurring. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) . 257--265 . https:\/\/doi.org\/10.1109\/CVPR. 2017 .35 10.1109\/CVPR.2017.35 S. Nah, T. H. Kim , and K. M. Lee. 2017. Deep Multi-scale Convolutional Neural Network for Dynamic Scene Deblurring. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) . 257--265. https:\/\/doi.org\/10.1109\/CVPR.2017.35"},{"key":"e_1_3_2_1_22_1","volume-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot , Patrick McDaniel , and Ian Goodfellow . 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 ( 2016 ). Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"C. I. Podilchuk and E. J. Delp. 2001. Digital watermarking: algorithms and applications. IEEE signal processing Magazine Vol. 18 4 (2001) 33--46.  C. I. Podilchuk and E. J. Delp. 2001. Digital watermarking: algorithms and applications. IEEE signal processing Magazine Vol. 18 4 (2001) 33--46.","DOI":"10.1109\/79.939835"},{"key":"e_1_3_2_1_24_1","volume-title":"The 24th ACM Int. Conf. on Architectural Support for Programming Languages and Operating Systems, Rhode Island, USA .","author":"Rouhani B","year":"2019","unstructured":"B Rouhani , H Darvish , and F Chen . 2019 . Deepsigns: an end-to-end watermarking framework for protecting the ownership of deep neural networks . In The 24th ACM Int. Conf. on Architectural Support for Programming Languages and Operating Systems, Rhode Island, USA . B Rouhani, H Darvish, and F Chen. 2019. Deepsigns: an end-to-end watermarking framework for protecting the ownership of deep neural networks. In The 24th ACM Int. Conf. on Architectural Support for Programming Languages and Operating Systems, Rhode Island, USA ."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9413062"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"#cr-split#-e_1_3_2_1_27_1.1","doi-asserted-by":"crossref","unstructured":"H. Wu G. Liu Y. Yao and X. Zhang. 2021. Watermarking Neural Networks with Watermarked Images. IEEE Transactions on Circuits and Systems for Video Technology (2021). https:\/\/doi.org\/10.1109\/TCSVT.2020.3030671 10.1109\/TCSVT.2020.3030671","DOI":"10.1109\/TCSVT.2020.3030671"},{"key":"#cr-split#-e_1_3_2_1_27_1.2","doi-asserted-by":"crossref","unstructured":"H. Wu G. Liu Y. Yao and X. Zhang. 2021. Watermarking Neural Networks with Watermarked Images. IEEE Transactions on Circuits and Systems for Video Technology (2021). https:\/\/doi.org\/10.1109\/TCSVT.2020.3030671","DOI":"10.1109\/TCSVT.2020.3030671"},{"key":"e_1_3_2_1_28_1","volume-title":"Generative Image Inpainting with Contextual Attention. In 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society","author":"Yu J.","year":"2018","unstructured":"J. Yu , Z. Lin , J. Yang , X. Shen , X. Lu , and T. S. Huang . 2018 . Generative Image Inpainting with Contextual Attention. In 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society , Los Alamitos, CA, USA, 5505--5514. https:\/\/doi.org\/10.1109\/CVPR. 2018 .00577 10.1109\/CVPR.2018.00577 J. Yu, Z. Lin, J. Yang, X. Shen, X. Lu, and T. S. Huang. 2018. Generative Image Inpainting with Contextual Attention. In 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society, Los Alamitos, CA, USA, 5505--5514. https:\/\/doi.org\/10.1109\/CVPR.2018.00577"},{"key":"e_1_3_2_1_29_1","volume-title":"Model Watermarking for Image Processing Networks. Proceedings of the AAAI Conference on Artificial Intelligence","volume":"34","author":"Zhang Jie","year":"2020","unstructured":"Jie Zhang , Dongdong Chen , Jing Liao , Han Fang , Weiming Zhang , Wenbo Zhou , Hao Cui , and Nenghai Yu . 2020 . Model Watermarking for Image Processing Networks. Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 34 , 07 (Apr. 2020), 12805--12812. https:\/\/doi.org\/10.1609\/aaai.v34i07.6976 10.1609\/aaai.v34i07.6976 Jie Zhang, Dongdong Chen, Jing Liao, Han Fang, Weiming Zhang, Wenbo Zhou, Hao Cui, and Nenghai Yu. 2020. Model Watermarking for Image Processing Networks. Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 34, 07 (Apr. 2020), 12805--12812. https:\/\/doi.org\/10.1609\/aaai.v34i07.6976"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2018.2839891"}],"event":{"name":"IH&MMSec '21: ACM Workshop on Information Hiding and Multimedia Security","location":"Virtual Event Belgium","acronym":"IH&MMSec '21","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3437880.3460399","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3437880.3460399","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:17:26Z","timestamp":1750191446000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3437880.3460399"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,17]]},"references-count":32,"alternative-id":["10.1145\/3437880.3460399","10.1145\/3437880"],"URL":"https:\/\/doi.org\/10.1145\/3437880.3460399","relation":{},"subject":[],"published":{"date-parts":[[2021,6,17]]},"assertion":[{"value":"2021-06-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}