{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:21:51Z","timestamp":1750220511326,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":25,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,6,17]],"date-time":"2021-06-17T00:00:00Z","timestamp":1623888000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,6,17]]},"DOI":"10.1145\/3437880.3460411","type":"proceedings-article","created":{"date-parts":[[2021,6,21]],"date-time":"2021-06-21T13:11:52Z","timestamp":1624281112000},"page":"81-86","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["iNNformant"],"prefix":"10.1145","author":[{"given":"Alexander","family":"Schl\u00f6gl","sequence":"first","affiliation":[{"name":"University of Innsbruck, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tobias","family":"Kupek","sequence":"additional","affiliation":[{"name":"Swarm Analytics GmbH, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rainer","family":"B\u00f6hme","sequence":"additional","affiliation":[{"name":"University of Innsbruck, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,6,21]]},"reference":[{"volume-title":"USENIX Security Symposium. 1615--1631","author":"Adi Yossi","key":"e_1_3_2_2_1_1","unstructured":"Yossi Adi , Carsten Baum , and Moustapha Ciss\u00e9 et al. 2018. Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring . In USENIX Security Symposium. 1615--1631 . Yossi Adi, Carsten Baum, and Moustapha Ciss\u00e9 et al. 2018. Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring. In USENIX Security Symposium. 1615--1631."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"e_1_3_2_2_3_1","volume-title":"Pascal Sch\u00f6 ttle, and Rainer B\u00f6 hme","author":"Carnein Matthias","year":"2016","unstructured":"Matthias Carnein , Pascal Sch\u00f6 ttle, and Rainer B\u00f6 hme . 2016 . Telltale Watermarks for Counting JPEG Compressions. In Media Watermarking . 1--10. Matthias Carnein, Pascal Sch\u00f6 ttle, and Rainer B\u00f6 hme. 2016. Telltale Watermarks for Counting JPEG Compressions. In Media Watermarking . 1--10."},{"key":"e_1_3_2_2_4_1","volume-title":"Bloom","author":"Cox Ingemar","year":"2007","unstructured":"Ingemar Cox , Matthew Miller , and Jeffrey et al. Bloom . 2007 . Digital Watermarking and Steganography . Ingemar Cox, Matthew Miller, and Jeffrey et al. Bloom. 2007. Digital Watermarking and Steganography ."},{"key":"e_1_3_2_2_5_1","volume-title":"ImageNet: A Large-Scale Hierarchical Image Database. In IEEE Conference on Computer Vision and Pattern Recognition, CVPR.","author":"Deng Jia","year":"2009","unstructured":"Jia Deng , Wei Dong , Richard Socher , Li-Jia Li , Kai Li , and Li Fei-Fei . 2009 . ImageNet: A Large-Scale Hierarchical Image Database. In IEEE Conference on Computer Vision and Pattern Recognition, CVPR. Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009. ImageNet: A Large-Scale Hierarchical Image Database. In IEEE Conference on Computer Vision and Pattern Recognition, CVPR."},{"key":"e_1_3_2_2_6_1","volume-title":"Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR), Y. Bengio and Y. LeCun (Eds.).","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR), Y. Bengio and Y. LeCun (Eds.). Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR), Y. Bengio and Y. LeCun (Eds.)."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240862"},{"volume-title":"Deep Residual Learning for Image Recognition. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778","author":"He Kaiming","key":"e_1_3_2_2_8_1","unstructured":"Kaiming He , Xiangyu Zhang , and Shaoqing Ren et al. 2016 . Deep Residual Learning for Image Recognition. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778 . Kaiming He, Xiangyu Zhang, and Shaoqing Ren et al. 2016. Deep Residual Learning for Image Recognition. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778."},{"key":"e_1_3_2_2_9_1","unstructured":"Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images . Master's thesis. Univ. of Toronto.  Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images . Master's thesis. Univ. of Toronto."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.771070"},{"key":"e_1_3_2_2_11_1","volume-title":"On the Difficulty of Hiding Keys in Neural Networks. In ACM Workshop on Information Hiding and Multimedia Security (IH & MMSec). 73--78","author":"Kupek Tobias","year":"2020","unstructured":"Tobias Kupek , Cecilia Pasquini , and Rainer B\u00f6 hme. 2020 . On the Difficulty of Hiding Keys in Neural Networks. In ACM Workshop on Information Hiding and Multimedia Security (IH & MMSec). 73--78 . Tobias Kupek, Cecilia Pasquini, and Rainer B\u00f6 hme. 2020. On the Difficulty of Hiding Keys in Neural Networks. In ACM Workshop on Information Hiding and Multimedia Security (IH & MMSec). 73--78."},{"volume-title":"Annual Computer Security Applications Conference (ACSAC). 126--137","author":"Li Zheng","key":"e_1_3_2_2_12_1","unstructured":"Zheng Li , Chengyu Hu , and Yang Zhang et al. 2019. How to prove your model belongs to you: a blind-watermark based framework to protect intellectual property of DNN . In Annual Computer Security Applications Conference (ACSAC). 126--137 . Zheng Li, Chengyu Hu, and Yang Zhang et al. 2019. How to prove your model belongs to you: a blind-watermark based framework to protect intellectual property of DNN . In Annual Computer Security Applications Conference (ACSAC). 126--137."},{"volume-title":"International Conference on Learning Representations (ICLR) .","author":"Madry Aleksander","key":"e_1_3_2_2_13_1","unstructured":"Aleksander Madry , Aleksandar Makelov , and Ludwig Schmidt et al. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks . In International Conference on Learning Representations (ICLR) . Aleksander Madry, Aleksandar Makelov, and Ludwig Schmidt et al. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations (ICLR) ."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Ryota Namba and Jun Sakuma. 2019. Robust Watermarking of Neural Network with Exponential Weighting. In Asia Conference on Computer and Communications Security (AsiaCCS) S. Galbraith G. Russello and W. Susilo et al. (Eds.). 228--240.  Ryota Namba and Jun Sakuma. 2019. Robust Watermarking of Neural Network with Exponential Weighting. In Asia Conference on Computer and Communications Security (AsiaCCS) S. Galbraith G. Russello and W. Susilo et al. (Eds.). 228--240.","DOI":"10.1145\/3321705.3329808"},{"volume-title":"SoK: Security and Privacy in Machine Learning. In IEEE European Symposium on Security and Privacy (EuroS&P). 399--414","author":"Papernot Nicolas","key":"e_1_3_2_2_16_1","unstructured":"Nicolas Papernot , Patrick D. McDaniel , and Arunesh Sinha et al. 2018 . SoK: Security and Privacy in Machine Learning. In IEEE European Symposium on Security and Privacy (EuroS&P). 399--414 . Nicolas Papernot, Patrick D. McDaniel, and Arunesh Sinha et al. 2018. SoK: Security and Privacy in Machine Learning. In IEEE European Symposium on Security and Privacy (EuroS&P). 399--414."},{"volume-title":"The Limitations of Deep Learning in Adversarial Settings. In IEEE European Symposium on Security and Privacy (EuroS&P). 372--387","author":"Papernot Nicolas","key":"e_1_3_2_2_17_1","unstructured":"Nicolas Papernot , Patrick D. McDaniel , and Somesh Jha et al. 2016 . The Limitations of Deep Learning in Adversarial Settings. In IEEE European Symposium on Security and Privacy (EuroS&P). 372--387 . Nicolas Papernot, Patrick D. McDaniel, and Somesh Jha et al. 2016. The Limitations of Deep Learning in Adversarial Settings. In IEEE European Symposium on Security and Privacy (EuroS&P). 372--387."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"crossref","unstructured":"Bita Darvish Rouhani Huili Chen and Farinaz Koushanfar. 2019. DeepSigns: An End-to-End Watermarking Framework for Ownership Protection of Deep Neural Networks. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS) . 485--497.  Bita Darvish Rouhani Huili Chen and Farinaz Koushanfar. 2019. DeepSigns: An End-to-End Watermarking Framework for Ownership Protection of Deep Neural Networks. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS) . 485--497.","DOI":"10.1145\/3297858.3304051"},{"key":"e_1_3_2_2_19_1","volume-title":"Forensicability of Deep Neural Network Inference Pipelines. In International Conference on Acoustics, Speech and Signal Processing (ICASSP) .","author":"Schl\u00f6gl Alexander","year":"2021","unstructured":"Alexander Schl\u00f6gl , Tobias Kupek , and Rainer B\u00f6hme . 2021 . Forensicability of Deep Neural Network Inference Pipelines. In International Conference on Acoustics, Speech and Signal Processing (ICASSP) . Alexander Schl\u00f6gl, Tobias Kupek, and Rainer B\u00f6hme. 2021. Forensicability of Deep Neural Network Inference Pipelines. In International Conference on Acoustics, Speech and Signal Processing (ICASSP) ."},{"key":"e_1_3_2_2_20_1","volume-title":"Towards Certifiable Adversarial Sample Detection. In ACM Workshop on Artificial Intelligence and Security (AISec). 13--24","author":"Shumailov Ilia","year":"2020","unstructured":"Ilia Shumailov , Yiren Zhao , Robert Mullins , and Ross Anderson . 2020 . Towards Certifiable Adversarial Sample Detection. In ACM Workshop on Artificial Intelligence and Security (AISec). 13--24 . Ilia Shumailov, Yiren Zhao, Robert Mullins, and Ross Anderson. 2020. Towards Certifiable Adversarial Sample Detection. In ACM Workshop on Artificial Intelligence and Security (AISec). 13--24."},{"volume-title":"Intriguing Properties of Neural Networks. In International Conference on Learning Representations (ICLR) .","author":"Szegedy Christian","key":"e_1_3_2_2_21_1","unstructured":"Christian Szegedy , Wojciech Zaremba , and Ilya Sutskever et al. 2014 . Intriguing Properties of Neural Networks. In International Conference on Learning Representations (ICLR) . Christian Szegedy, Wojciech Zaremba, and Ilya Sutskever et al. 2014. Intriguing Properties of Neural Networks. In International Conference on Learning Representations (ICLR) ."},{"volume-title":"International Conference on Multimedia Retrieval (ICMR), B. Ionescu, B. Sebe, and J. Feng et al. (Eds.). 269--277","author":"Uchida Yusuke","key":"e_1_3_2_2_22_1","unstructured":"Yusuke Uchida , Yuki Nagai , and Shigeyuki Sakazawa et al. 2017. Embedding Watermarks into Deep Neural Networks . In International Conference on Multimedia Retrieval (ICMR), B. Ionescu, B. Sebe, and J. Feng et al. (Eds.). 269--277 . Yusuke Uchida, Yuki Nagai, and Shigeyuki Sakazawa et al. 2017. Embedding Watermarks into Deep Neural Networks. In International Conference on Multimedia Retrieval (ICMR), B. Ionescu, B. Sebe, and J. Feng et al. (Eds.). 269--277."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"crossref","unstructured":"Stephen T. Welstead. 1999. Fractal and Wavelet Image Compression Techniques .  Stephen T. Welstead. 1999. Fractal and Wavelet Image Compression Techniques .","DOI":"10.1117\/3.353798"},{"key":"e_1_3_2_2_24_1","unstructured":"Han Xiao Kashif Rasul and Roland Vollgraf. 2017. Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms. http:\/\/arxiv.org\/abs\/1708.07747 arXiv Computing Research Repository (CoRR) abs\/1708.07747.  Han Xiao Kashif Rasul and Roland Vollgraf. 2017. Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms. http:\/\/arxiv.org\/abs\/1708.07747 arXiv Computing Research Repository (CoRR) abs\/1708.07747."},{"volume-title":"Protecting Intellectual Property of Deep Neural Networks with Watermarking. In Asia Conference on Computer and Communications Security (AsiaCCS) . 159--172","author":"Zhang Jialong","key":"e_1_3_2_2_25_1","unstructured":"Jialong Zhang , Zhongshu Gu , and Jiyong Jang et al. 2018 . Protecting Intellectual Property of Deep Neural Networks with Watermarking. In Asia Conference on Computer and Communications Security (AsiaCCS) . 159--172 . Jialong Zhang, Zhongshu Gu, and Jiyong Jang et al. 2018. Protecting Intellectual Property of Deep Neural Networks with Watermarking. In Asia Conference on Computer and Communications Security (AsiaCCS) . 159--172."}],"event":{"name":"IH&MMSec '21: ACM Workshop on Information Hiding and Multimedia Security","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Virtual Event Belgium","acronym":"IH&MMSec '21"},"container-title":["Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3437880.3460411","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3437880.3460411","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:26Z","timestamp":1750195466000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3437880.3460411"}},"subtitle":["Boundary Samples as Telltale Watermarks"],"short-title":[],"issued":{"date-parts":[[2021,6,17]]},"references-count":25,"alternative-id":["10.1145\/3437880.3460411","10.1145\/3437880"],"URL":"https:\/\/doi.org\/10.1145\/3437880.3460411","relation":{},"subject":[],"published":{"date-parts":[[2021,6,17]]},"assertion":[{"value":"2021-06-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}