{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T05:24:26Z","timestamp":1781587466348,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":18,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,21]],"date-time":"2023-10-21T00:00:00Z","timestamp":1697846400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["NS-1816497,IIS-1849085,IS-2224843"],"award-info":[{"award-number":["NS-1816497,IIS-1849085,IS-2224843"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,21]]},"DOI":"10.1145\/3583780.3615211","type":"proceedings-article","created":{"date-parts":[[2023,10,21]],"date-time":"2023-10-21T07:45:42Z","timestamp":1697874342000},"page":"4315-4319","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Exposing Model Theft: A Robust and Transferable Watermark for Thwarting Model Extraction Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6476-2336","authenticated-orcid":false,"given":"Ruixiang","family":"Tang","sequence":"first","affiliation":[{"name":"Rice University, Houston, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7920-632X","authenticated-orcid":false,"given":"Hongye","family":"Jin","sequence":"additional","affiliation":[{"name":"Texas A&amp;M Univeristy, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1614-6069","authenticated-orcid":false,"given":"Mengnan","family":"Du","sequence":"additional","affiliation":[{"name":"New Jersey Institute of Technology, Newark, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-2051-0043","authenticated-orcid":false,"given":"Curtis","family":"Wigington","sequence":"additional","affiliation":[{"name":"Adobe, San Francisco, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8305-2206","authenticated-orcid":false,"given":"Rajiv","family":"Jain","sequence":"additional","affiliation":[{"name":"Adobe, San Francisco, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2234-3226","authenticated-orcid":false,"given":"Xia","family":"Hu","sequence":"additional","affiliation":[{"name":"Rice Univeristy, Houston, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,10,21]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi , Carsten Baum , Moustapha Cisse , Benny Pinkas , and Joseph Keshet . 2018 . Turning your weakness into a strength: Watermarking deep neural networks by backdooring . In 27th USENIX Security Symposium (USENIX Security 18) . 1615--1631. Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX Security Symposium (USENIX Security 18). 1615--1631."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_1_3_1","unstructured":"Robert V Hogg Joseph McKean and Allen T Craig. 2005. Introduction to mathematical statistics. Pearson Education.  Robert V Hogg Joseph McKean and Allen T Craig. 2005. Introduction to mathematical statistics. Pearson Education."},{"key":"e_1_3_2_1_4_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Jia Hengrui","year":"2021","unstructured":"Hengrui Jia , Christopher A Choquette-Choo , Varun Chandrasekaran , and Nicolas Papernot . 2021 . Entangled watermarks as a defense against model extraction . In 30th USENIX Security Symposium (USENIX Security 21) . 1937--1954. Hengrui Jia, Christopher A Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot. 2021. Entangled watermarks as a defense against model extraction. In 30th USENIX Security Symposium (USENIX Security 21). 1937--1954."},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of NAACL-HLT. 4171--4186","author":"Ming-Wei Chang Jacob Devlin","year":"2019","unstructured":"Jacob Devlin Ming-Wei Chang Kenton and Lee Kristina Toutanova . 2019 . BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding . In Proceedings of NAACL-HLT. 4171--4186 . Jacob Devlin Ming-Wei Chang Kenton and Lee Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In Proceedings of NAACL-HLT. 4171--4186."},{"key":"e_1_3_2_1_6_1","volume-title":"International Conference on Machine Learning. PMLR, 3519--3529","author":"Kornblith Simon","year":"2019","unstructured":"Simon Kornblith , Mohammad Norouzi , Honglak Lee , and Geoffrey Hinton . 2019 . Similarity of neural network representations revisited . In International Conference on Machine Learning. PMLR, 3519--3529 . Simon Kornblith, Mohammad Norouzi, Honglak Lee, and Geoffrey Hinton. 2019. Similarity of neural network representations revisited. In International Conference on Machine Learning. PMLR, 3519--3529."},{"key":"e_1_3_2_1_7_1","volume-title":"International Conference on Learning Representations.","author":"Krishna Kalpesh","year":"2019","unstructured":"Kalpesh Krishna , Gaurav Singh Tomar , Ankur P Parikh , Nicolas Papernot , and Mohit Iyyer . 2019 . Thieves on Sesame Street! Model Extraction of BERT-based APIs . In International Conference on Learning Representations. Kalpesh Krishna, Gaurav Singh Tomar, Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer. 2019. Thieves on Sesame Street! Model Extraction of BERT-based APIs. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_9_1","volume-title":"DivTheft: An Ensemble Model Stealing Attack by Divide-and-Conquer","author":"Ma Zhuo","year":"2023","unstructured":"Zhuo Ma , Xinjing Liu , Yang Liu , Ximeng Liu , Zhan Qin , and Kui Ren . 2023. DivTheft: An Ensemble Model Stealing Attack by Divide-and-Conquer . IEEE Transactions on Dependable and Secure Computing ( 2023 ). Zhuo Ma, Xinjing Liu, Yang Liu, Ximeng Liu, Zhan Qin, and Kui Ren. 2023. DivTheft: An Ensemble Model Stealing Attack by Divide-and-Conquer. IEEE Transactions on Dependable and Secure Computing (2023)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_1_11_1","volume-title":"Prediction poisoning: Towards defenses against dnn model stealing attacks. arXiv preprint arXiv:1906.10908","author":"Orekondy Tribhuvanesh","year":"2019","unstructured":"Tribhuvanesh Orekondy , Bernt Schiele , and Mario Fritz . 2019b. Prediction poisoning: Towards defenses against dnn model stealing attacks. arXiv preprint arXiv:1906.10908 ( 2019 ). Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2019b. Prediction poisoning: Towards defenses against dnn model stealing attacks. arXiv preprint arXiv:1906.10908 (2019)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"e_1_3_2_1_13_1","volume-title":"Deep serial number: Computational watermarking for DNN intellectual property protection. arXiv preprint arXiv:2011.08960","author":"Tang Ruixiang","year":"2020","unstructured":"Ruixiang Tang , Mengnan Du , and Xia Hu. 2020a. Deep serial number: Computational watermarking for DNN intellectual property protection. arXiv preprint arXiv:2011.08960 ( 2020 ). Ruixiang Tang, Mengnan Du, and Xia Hu. 2020a. Deep serial number: Computational watermarking for DNN intellectual property protection. arXiv preprint arXiv:2011.08960 (2020)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"e_1_3_2_1_15_1","first-page":"1","article-title":"Did You Train on My Dataset","volume":"25","author":"Tang Ruixiang","year":"2023","unstructured":"Ruixiang Tang , Qizhang Feng , Ninghao Liu , Fan Yang , and Xia Hu . 2023 . Did You Train on My Dataset ? Towards Public Dataset Protection with CleanLabel Backdoor Watermarking. SIGKDD Explor. Newsl. , Vol. 25 , 1 (jul 2023), 43--53. https:\/\/doi.org\/10.1145\/3606274.3606279 10.1145\/3606274.3606279 Ruixiang Tang, Qizhang Feng, Ninghao Liu, Fan Yang, and Xia Hu. 2023. Did You Train on My Dataset? Towards Public Dataset Protection with CleanLabel Backdoor Watermarking. SIGKDD Explor. Newsl. , Vol. 25, 1 (jul 2023), 43--53. https:\/\/doi.org\/10.1145\/3606274.3606279","journal-title":"Towards Public Dataset Protection with CleanLabel Backdoor Watermarking. SIGKDD Explor. Newsl."},{"key":"e_1_3_2_1_16_1","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r , Fan Zhang , Ari Juels , Michael K Reiter , and Thomas Ristenpart . 2016 . Stealing machine learning models via prediction apis . In 25th USENIX Security Symposium (USENIX Security 16) . 601--618. Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction apis. In 25th USENIX Security Symposium (USENIX Security 16). 601--618."},{"key":"e_1_3_2_1_17_1","volume-title":"Explanation leaks: Explanation-guided model extraction attacks. Information Sciences","author":"Yan Anli","year":"2023","unstructured":"Anli Yan , Teng Huang , Lishan Ke , Xiaozhang Liu , Qi Chen , and Changyu Dong . 2023. Explanation leaks: Explanation-guided model extraction attacks. Information Sciences ( 2023 ). Anli Yan, Teng Huang, Lishan Ke, Xiaozhang Liu, Qi Chen, and Changyu Dong. 2023. Explanation leaks: Explanation-guided model extraction attacks. Information Sciences (2023)."},{"key":"e_1_3_2_1_18_1","volume-title":"Deep learning. nature","author":"Yan Le Cun","year":"2015","unstructured":"Le Cun Yan , B Yoshua , and H Geoffrey . 2015. Deep learning. nature , Vol. 521 , 7553 ( 2015 ), 436--444. Le Cun Yan, B Yoshua, and H Geoffrey. 2015. Deep learning. nature, Vol. 521, 7553 (2015), 436--444."}],"event":{"name":"CIKM '23: The 32nd ACM International Conference on Information and Knowledge Management","location":"Birmingham United Kingdom","acronym":"CIKM '23","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web","SIGIR ACM Special Interest Group on Information Retrieval"]},"container-title":["Proceedings of the 32nd ACM International Conference on Information and Knowledge Management"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3583780.3615211","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3583780.3615211","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3583780.3615211","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:58Z","timestamp":1750178218000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3583780.3615211"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,21]]},"references-count":18,"alternative-id":["10.1145\/3583780.3615211","10.1145\/3583780"],"URL":"https:\/\/doi.org\/10.1145\/3583780.3615211","relation":{},"subject":[],"published":{"date-parts":[[2023,10,21]]},"assertion":[{"value":"2023-10-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}