{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T16:15:25Z","timestamp":1783527325551,"version":"3.55.0"},"reference-count":36,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2024,12,24]],"date-time":"2024-12-24T00:00:00Z","timestamp":1734998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62072250, U23A20305, U23B2022, 62371145, 62072480, 62172435, 62302249, 62272255, 62302248, U20B2065"],"award-info":[{"award-number":["62072250, U23A20305, U23B2022, 62371145, 62072480, 62172435, 62302249, 62272255, 62302248, U20B2065"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Zhongyuan Science and Technology Innovation Leading Talent Project of China","award":["214200510019"],"award-info":[{"award-number":["214200510019"]}]},{"name":"Open Foundation of Henan Key Laboratory of Cyberspace Situation Awareness","award":["HNTS2022002"],"award-info":[{"award-number":["HNTS2022002"]}]},{"name":"Graduate Student Scientific Research Innovation Projects of Jiangsu Province","award":["KYCX23_1359"],"award-info":[{"award-number":["KYCX23_1359"]}]},{"name":"Open Project the State Key Laboratory of Tibetan Intelligent Information Processing and Application and Key Laboratory","award":["2024-Z-003"],"award-info":[{"award-number":["2024-Z-003"]}]},{"name":"Open Project Fund of Shandong Provincial Key Laboratory of Computer Network","award":["SDKLCN-2022-05"],"award-info":[{"award-number":["SDKLCN-2022-05"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Multimedia Comput. Commun. Appl."],"published-print":{"date-parts":[[2025,2,28]]},"abstract":"<jats:p>Invisible watermarking can be used as an important tool for copyright certification in the Metaverse. However, with the advent of deep learning, Deep Neural Networks (DNNs) have posed new threats to this technique. For example, artificially trained DNNs can perform unauthorized content analysis and achieve illegal access to protected images. Furthermore, some specially crafted DNNs may even erase invisible watermarks embedded within the protected images, which eventually leads to the collapse of this protection and certification mechanism. To address these issues, inspired by the adversarial attack, we introduce Invisible Adversarial Watermarking (IAW), a novel security mechanism to enhance the copyright protection efficacy of watermarks. Specifically, we design an Adversarial Watermarking Fusion Model (AWFM) to efficiently generate Invisible Adversarial Watermark Images (IAWIs). By modeling the embedding of watermarks and adversarial perturbations as a unified task, the generated IAWIs can effectively defend against unauthorized identification, access, and erase via DNNs and identify the ownership by extracting the embedded watermark. Experimental results show that the proposed IAW presents superior extraction accuracy, attack ability, and robustness on different DNNs, and the protected images maintain good visual quality, which ensures its effectiveness as an image protection mechanism.<\/jats:p>","DOI":"10.1145\/3652608","type":"journal-article","created":{"date-parts":[[2024,3,14]],"date-time":"2024-03-14T12:23:51Z","timestamp":1710419031000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["Invisible Adversarial Watermarking: A Novel Security Mechanism for Enhancing Copyright Protection"],"prefix":"10.1145","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9366-5671","authenticated-orcid":false,"given":"Jinwei","family":"Wang","sequence":"first","affiliation":[{"name":"School of Computer and Software, Engineering Research Center of Digital Forensics, Ministry of Education, Nanjing University of Information Science and Technology, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-1695-9505","authenticated-orcid":false,"given":"Haihua","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer and Software, Nanjing University of Information Science and Technology, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1745-7763","authenticated-orcid":false,"given":"Jiawei","family":"Zhang","sequence":"additional","affiliation":[{"name":"computer and software, Nanjing University of Information Science and Technology, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2324-2152","authenticated-orcid":false,"given":"Hao","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Computer and Software, Nanjing University of Information Science and Technology, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3225-4649","authenticated-orcid":false,"given":"Xiangyang","family":"Luo","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9030-7393","authenticated-orcid":false,"given":"Bin","family":"Ma","sequence":"additional","affiliation":[{"name":"Qilu University of Technology, Jinan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,24]]},"reference":[{"key":"e_1_3_3_2_2","first-page":"734","volume-title":"2nd International Conference on Consumer Electronics and Computer Engineering (ICCECE\u201922)","author":"Cao Yangjie","year":"2022","unstructured":"Yangjie Cao, Mingli Lu, Shuling Li, Yan Zhuang, and Aosong Yang. 2022. Adversarial watermark based image privacy protection algorithm. In 2nd International Conference on Consumer Electronics and Computer Engineering (ICCECE\u201922). IEEE, 734\u2013741."},{"key":"e_1_3_3_3_2","first-page":"39","volume-title":"IEEE Symposium on Security and Privacy (SP\u201917)","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In IEEE Symposium on Security and Privacy (SP\u201917). IEEE, 39\u201357."},{"key":"e_1_3_3_4_2","first-page":"243","volume-title":"3rd IEEE International Conference on Image Processing","author":"Cox Ingemar J.","year":"1996","unstructured":"Ingemar J. Cox, Joe Kilian, Tom Leighton, and Talal Shamoon. 1996. Secure spread spectrum watermarking for images, audio and video. In 3rd IEEE International Conference on Image Processing. IEEE, 243\u2013246."},{"key":"e_1_3_3_5_2","unstructured":"Emily L. Denton Soumith Chintala Arthur Szlam and Rob Fergus. 2015. Deep generative image models using a Laplacian pyramid of adversarial networks. Adv. Neural Inf. Process. Syst. 28 (2015)."},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_3_7_2","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014).","journal-title":"arXiv preprint arXiv:1412.6572"},{"key":"e_1_3_3_8_2","unstructured":"Gregory Griffin Alex Holub and Pietro Perona. 2007. Caltech-256 object category dataset. https:\/\/data.caltech.edu\/records\/20087"},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.771066"},{"key":"e_1_3_3_10_2","first-page":"6858","volume-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Hertz Amir","year":"2019","unstructured":"Amir Hertz, Sharon Fogel, Rana Hanocka, Raja Giryes, and Daniel Cohen-Or. 2019. Blind visual motif removal from a single image. In IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 6858\u20136867."},{"key":"e_1_3_3_11_2","first-page":"170","volume-title":"Ethics of Data and Analytics","author":"Hill Kashmir","year":"2020","unstructured":"Kashmir Hill. 2020. The secretive company that might end privacy as we know it. In Ethics of Data and Analytics. Auerbach Publications, 170\u2013177."},{"key":"e_1_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.632"},{"key":"e_1_3_3_13_2","volume-title":"IEEE\/CVF International Conference on Computer Vision Workshops","author":"Jandial Surgan","year":"2019","unstructured":"Surgan Jandial, Puneet Mangla, Sakshi Varshney, and Vineeth Balasubramanian. 2019. AdvGAN++: Harnessing latent layers for adversary generation. In IEEE\/CVF International Conference on Computer Vision Workshops."},{"key":"e_1_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413976"},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475324"},{"key":"e_1_3_3_16_2","article-title":"FAWA: Fast adversarial watermark attack","author":"Jiang Hao","year":"2021","unstructured":"Hao Jiang, Jintao Yang, Guang Hua, Lixia Li, Ying Wang, Shenghui Tu, and Song Xia. 2021. FAWA: Fast adversarial watermark attack. IEEE Trans. Comput. 73, 2 (2021), 301\u2013313.","journal-title":"IEEE Trans. Comput."},{"key":"e_1_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-017-4941-1"},{"key":"e_1_3_3_18_2","article-title":"Adam: A method for stochastic optimization","author":"Kingma Diederik P.","year":"2014","unstructured":"Diederik P. Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014).","journal-title":"arXiv preprint arXiv:1412.6980"},{"key":"e_1_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46487-9_43"},{"key":"e_1_3_3_20_2","first-page":"241","volume-title":"16th European Conference on Computer Vision (ECCV\u201920)","author":"Li Qizhang","year":"2020","unstructured":"Qizhang Li, Yiwen Guo, and Hao Chen. 2020. Yet another intermediate-level attack. In 16th European Conference on Computer Vision (ECCV\u201920). Springer, 241\u2013257."},{"key":"e_1_3_3_21_2","first-page":"1","volume-title":"European Conference on Computer Vision","author":"Liu Xinwei","year":"2022","unstructured":"Xinwei Liu, Jian Liu, Yang Bai, Jindong Gu, Tao Chen, Xiaojun Jia, and Xiaochun Cao. 2022. Watermark vaccine: Adversarial attacks to prevent watermark removal. In European Conference on Computer Vision. Springer, 1\u201317."},{"key":"e_1_3_3_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3351025"},{"key":"e_1_3_3_23_2","first-page":"3685","volume-title":"IEEE\/CVF Winter Conference on Applications of Computer Vision","author":"Liu Yang","year":"2021","unstructured":"Yang Liu, Zhen Zhu, and Xiang Bai. 2021. WDNet: Watermark-decomposition network for visible watermark removal. In IEEE\/CVF Winter Conference on Applications of Computer Vision. 3685\u20133693."},{"key":"e_1_3_3_24_2","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017).","journal-title":"arXiv preprint arXiv:1706.06083"},{"key":"e_1_3_3_25_2","article-title":"Defeating image obfuscation with deep learning","author":"McPherson Richard","year":"2016","unstructured":"Richard McPherson, Reza Shokri, and Vitaly Shmatikov. 2016. Defeating image obfuscation with deep learning. arXiv preprint arXiv:1609.00408 (2016).","journal-title":"arXiv preprint arXiv:1609.00408"},{"key":"e_1_3_3_26_2","volume-title":"WIRED","author":"Newman Lily Hay","year":"2016","unstructured":"Lily Hay Newman. 2016. AI can recognize your face even if you\u2019re pixelated. In WIRED. https:\/\/www.wired.com\/2016\/09\/machine-learning-canidentify-pixelated-facesresearchers-show\/"},{"key":"e_1_3_3_27_2","first-page":"234","volume-title":"18th International Conference on Medical Image Computing and Computer-Assisted Intervention (MICCAI\u201915)","author":"Ronneberger Olaf","year":"2015","unstructured":"Olaf Ronneberger, Philipp Fischer, and Thomas Brox. 2015. U-net: Convolutional networks for biomedical image segmentation. In 18th International Conference on Medical Image Computing and Computer-Assisted Intervention (MICCAI\u201915). Springer, 234\u2013241."},{"key":"e_1_3_3_28_2","first-page":"13950","article-title":"Learning transferable adversarial perturbations","volume":"34","year":"2021","unstructured":"Krishna kanthNakka and Mathieu Salzmann. 2021. Learning transferable adversarial perturbations. Adv. Neural Inf. Process. Syst. 34 (2021), 13950\u201313962.","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_3_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"e_1_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3111195"},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.sigpro.2022.108818"},{"key":"e_1_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01234-2_1"},{"key":"e_1_3_3_33_2","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1007\/978-3-031-25115-3_6","volume-title":"21st International Workshop on Digital Forensics and Watermarking","author":"Wu Hao","year":"2023","unstructured":"Hao Wu, Jinwei Wang, Jiawei Zhang, Xiangyang Luo, and Bin Ma. 2023. Improving the transferability of adversarial attacks through both front and rear vector method. In 21st International Workshop on Digital Forensics and Watermarking. Springer, 83\u201397."},{"key":"e_1_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.5555\/3304222.3304312"},{"key":"e_1_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2018.2837381"},{"key":"e_1_3_3_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2022.3207008"},{"key":"e_1_3_3_37_2","first-page":"657","volume-title":"European Conference on Computer Vision (ECCV\u201918)","author":"Zhu Jiren","year":"2018","unstructured":"Jiren Zhu, Russell Kaplan, Justin Johnson, and Li Fei-Fei. 2018. Hidden: Hiding data with deep networks. In European Conference on Computer Vision (ECCV\u201918). 657\u2013672."}],"container-title":["ACM Transactions on Multimedia Computing, Communications, and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3652608","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3652608","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:03:30Z","timestamp":1750291410000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3652608"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,24]]},"references-count":36,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,2,28]]}},"alternative-id":["10.1145\/3652608"],"URL":"https:\/\/doi.org\/10.1145\/3652608","relation":{},"ISSN":["1551-6857","1551-6865"],"issn-type":[{"value":"1551-6857","type":"print"},{"value":"1551-6865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,24]]},"assertion":[{"value":"2023-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-03-09","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}