{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T16:28:18Z","timestamp":1783787298233,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":21,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,6,17]],"date-time":"2021-06-17T00:00:00Z","timestamp":1623888000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Iotwins","award":["8571911"],"award-info":[{"award-number":["8571911"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,6,17]]},"DOI":"10.1145\/3437880.3460409","type":"proceedings-article","created":{"date-parts":[[2021,6,21]],"date-time":"2021-06-21T13:11:52Z","timestamp":1624281112000},"page":"171-176","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["A Protocol for Secure Verification of Watermarks Embedded into Machine Learning Models"],"prefix":"10.1145","author":[{"given":"Katarzyna","family":"Kapusta","sequence":"first","affiliation":[{"name":"Thales SIX GTS, Palaiseau, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vincent","family":"Thouvenot","sequence":"additional","affiliation":[{"name":"Thales SIX GTS, Palaiseau, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Olivier","family":"Bettan","sequence":"additional","affiliation":[{"name":"Thales SIX GTS, Palaiseau, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hugo","family":"Beguinet","sequence":"additional","affiliation":[{"name":"Thales SIX GTS, Cholet, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hugo","family":"Senet","sequence":"additional","affiliation":[{"name":"Thales SIX GTS, Gennevilliers, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,6,21]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi , Carsten Baum , Moustapha Cisse , Benny Pinkas , and Joseph Keshet . 2018 . Turning your weakness into a strength: Watermarking deep neural networks by backdooring . In 27th USENIX Security Symposium (USENIX Security 18) (2018). Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX Security Symposium (USENIX Security 18) (2018)."},{"key":"e_1_3_2_2_2_1","volume-title":"Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728","author":"Chen Bryant","year":"2018","unstructured":"Bryant Chen , Wilka Carvalho , Nathalie Baracaldo , Heiko Ludwig , Benjamin Edwards , Taesung Lee , Ian Molloy , and Biplav Srivastava . 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 ( 2018 ). Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018)."},{"key":"e_1_3_2_2_3_1","volume-title":"Cheng Fu, Jishen Zhao, and Farinaz Koushanfar.","author":"Chen Huili","year":"2019","unstructured":"Huili Chen , Bita Darvish Rouhani , Cheng Fu, Jishen Zhao, and Farinaz Koushanfar. 2019 . DeepMarks: A Secure Fingerprinting Framework for Digital Rights Management of Deep Learning Models . (2019), 105--113. https:\/\/doi.org\/10.1145\/3323873.3325042 10.1145\/3323873.3325042 Huili Chen, Bita Darvish Rouhani, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar. 2019. DeepMarks: A Secure Fingerprinting Framework for Digital Rights Management of Deep Learning Models. (2019), 105--113. https:\/\/doi.org\/10.1145\/3323873.3325042"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"#cr-split#-e_1_3_2_2_5_1.1","unstructured":"Emiliano De Cristofaro Paolo Gasti and Gene Tsudik. 2012. Fast and Private Computation of Cardinality of Set Intersection and Union. https:\/\/doi.org\/10.1007\/978--3--642--35404--5_17 10.1007\/978--3--642--35404--5_17"},{"key":"#cr-split#-e_1_3_2_2_5_1.2","doi-asserted-by":"crossref","unstructured":"Emiliano De Cristofaro Paolo Gasti and Gene Tsudik. 2012. Fast and Private Computation of Cardinality of Set Intersection and Union. https:\/\/doi.org\/10.1007\/978--3--642--35404--5_17","DOI":"10.1007\/978-3-642-35404-5_17"},{"key":"e_1_3_2_2_6_1","first-page":"6","article-title":"New Directions in Cryptography","volume":"22","author":"Diffie Whitfield","year":"2006","unstructured":"Whitfield Diffie and Martin Hellman . 2006 . New Directions in Cryptography . IEEE Trans. Inf. Theor. , Vol. 22 , 6 (Sept. 2006), 644--654. https:\/\/doi.org\/10.1109\/TIT.1976.1055638 10.1109\/TIT.1976.1055638 Whitfield Diffie and Martin Hellman. 2006. New Directions in Cryptography. IEEE Trans. Inf. Theor. , Vol. 22, 6 (Sept. 2006), 644--654. https:\/\/doi.org\/10.1109\/TIT.1976.1055638","journal-title":"IEEE Trans. Inf. Theor."},{"key":"e_1_3_2_2_7_1","volume-title":"Kam Woh Ng, and Chee Sang Chan","author":"Fan Lixin","year":"2019","unstructured":"Lixin Fan , Kam Woh Ng, and Chee Sang Chan . 2019 . Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attack. Advances in Neural Information Processing Systems (NIPS) ( 2019). Lixin Fan, Kam Woh Ng, and Chee Sang Chan. 2019. Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attack. Advances in Neural Information Processing Systems (NIPS) (2019)."},{"key":"e_1_3_2_2_8_1","volume-title":"Sarvar Patel, Mariana Raykova, Shobhit Saxena, Karn Seth, David Shanahan, and Moti Yung.","author":"Ion Mihaela","year":"2019","unstructured":"Mihaela Ion , Ben Kreuter , Ahmet Erhan Nergiz , Sarvar Patel, Mariana Raykova, Shobhit Saxena, Karn Seth, David Shanahan, and Moti Yung. 2019 . On Deploying Secure Computing: Private Intersection-Sum-with-Cardinality. Cryptology ePrint Archive, Report 2019\/723. https:\/\/eprint.iacr.org\/2019\/723. Mihaela Ion, Ben Kreuter, Ahmet Erhan Nergiz, Sarvar Patel, Mariana Raykova, Shobhit Saxena, Karn Seth, David Shanahan, and Moti Yung. 2019. On Deploying Secure Computing: Private Intersection-Sum-with-Cardinality. Cryptology ePrint Archive, Report 2019\/723. https:\/\/eprint.iacr.org\/2019\/723."},{"key":"e_1_3_2_2_9_1","volume-title":"Conference on Artificial Intelligence for Defense (CAID)","author":"Kapusta Katarzyna","year":"2020","unstructured":"Katarzyna Kapusta , Vincent Thouvenot , and Olivier Bettan . 2020 . Watermarking at the service of intellectualproperty rights of ML models . Conference on Artificial Intelligence for Defense (CAID) (2020). Katarzyna Kapusta, Vincent Thouvenot, and Olivier Bettan. 2020. Watermarking at the service of intellectualproperty rights of ML models. Conference on Artificial Intelligence for Defense (CAID) (2020)."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359801"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_12_1","volume-title":"The TAMARIN Prover for the Symbolic Analysis of Security Protocols","author":"Meier Simon","unstructured":"Simon Meier , Benedikt Schmidt , Cas Cremers , and David Basin . 2013. The TAMARIN Prover for the Symbolic Analysis of Security Protocols . In Computer Aided Verification, Natasha Sharygina and Helmut Veith (Eds.). Springer Berlin Heidelberg , Berlin, Heidelberg , 696--701. Simon Meier, Benedikt Schmidt, Cas Cremers, and David Basin. 2013. The TAMARIN Prover for the Symbolic Analysis of Security Protocols. In Computer Aided Verification, Natasha Sharygina and Helmut Veith (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 696--701."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329808"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/1756123.1756146"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Benny Pinkas M. Rosulek Ni Trieu and A. Yanai. 2020. PSI from PaXoS: Fast Malicious Private Set Intersection. In IACR Cryptol. ePrint Arch.  Benny Pinkas M. Rosulek Ni Trieu and A. Yanai. 2020. PSI from PaXoS: Fast Malicious Private Set Intersection. In IACR Cryptol. ePrint Arch.","DOI":"10.1007\/978-3-030-45724-2_25"},{"key":"e_1_3_2_2_16_1","unstructured":"T. T. Team. [n.d.]. Tamarin-prover manual. http:\/\/tamarin-prover.github.io\/  T. T. Team. [n.d.]. Tamarin-prover manual. http:\/\/tamarin-prover.github.io\/"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"e_1_3_2_2_18_1","volume-title":"RIGA: Covert and Robust White-Box Watermarking of Deep Neural Networks. arXiv: Cryptography and Security","author":"Wang Tianhao","year":"2020","unstructured":"Tianhao Wang and Florian Kerschbaum . 2020 . RIGA: Covert and Robust White-Box Watermarking of Deep Neural Networks. arXiv: Cryptography and Security (2020). Tianhao Wang and Florian Kerschbaum. 2020. RIGA: Covert and Robust White-Box Watermarking of Deep Neural Networks. arXiv: Cryptography and Security (2020)."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"e_1_3_2_2_20_1","unstructured":"ZKProof. 2019. ZKProof Community Reference.  ZKProof. 2019. ZKProof Community Reference."}],"event":{"name":"IH&MMSec '21: ACM Workshop on Information Hiding and Multimedia Security","location":"Virtual Event Belgium","acronym":"IH&MMSec '21","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3437880.3460409","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3437880.3460409","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:26Z","timestamp":1750195466000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3437880.3460409"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,17]]},"references-count":21,"alternative-id":["10.1145\/3437880.3460409","10.1145\/3437880"],"URL":"https:\/\/doi.org\/10.1145\/3437880.3460409","relation":{},"subject":[],"published":{"date-parts":[[2021,6,17]]},"assertion":[{"value":"2021-06-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}