{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T19:45:51Z","timestamp":1775591151686,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":81,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,10,28]],"date-time":"2024-10-28T00:00:00Z","timestamp":1730073600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/https:\/\/doi.org\/10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["No.2023M741950"],"award-info":[{"award-number":["No.2023M741950"]}],"id":[{"id":"10.13039\/https:\/\/doi.org\/10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Nationally Funded Postdoctoral Researcher Program","award":["No.GZB20230347"],"award-info":[{"award-number":["No.GZB20230347"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,10,28]]},"DOI":"10.1145\/3664647.3681418","type":"proceedings-article","created":{"date-parts":[[2024,10,26]],"date-time":"2024-10-26T06:59:41Z","timestamp":1729925981000},"page":"7113-7122","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Safe-SD: Safe and Traceable Stable Diffusion with Text Prompt Trigger for Invisible Generative Watermarking"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-3756-5621","authenticated-orcid":false,"given":"Zhiyuan","family":"Ma","sequence":"first","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9494-7013","authenticated-orcid":false,"given":"Guoli","family":"Jia","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4072-0577","authenticated-orcid":false,"given":"Biqing","family":"Qi","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1062-9526","authenticated-orcid":false,"given":"Bowen","family":"Zhou","sequence":"additional","affiliation":[{"name":"Tsinghua University &amp; Shanghai AI Laboratory, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,10,28]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX Security Symposium (USENIX Security 18). 1615--1631."},{"key":"e_1_3_2_2_2_1","volume-title":"Hiding images within images","author":"Baluja Shumeet","year":"2019","unstructured":"Shumeet Baluja. 2019. Hiding images within images. IEEE transactions on pattern analysis and machine intelligence 42, 7 (2019), 1685--1697."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01764"},{"key":"e_1_3_2_2_4_1","volume-title":"Muse: Text-to-image generation via masked generative transformers. arXiv preprint arXiv:2301.00704","author":"Chang Huiwen","year":"2023","unstructured":"Huiwen Chang, Han Zhang, Jarred Barber, AJ Maschinot, Jose Lezama, Lu Jiang, Ming-Hsuan Yang, Kevin Murphy, William T Freeman, Michael Rubinstein, et al. 2023. Muse: Text-to-image generation via masked generative transformers. arXiv preprint arXiv:2301.00704 (2023)."},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3323873.3325042"},{"key":"e_1_3_2_2_6_1","volume-title":"Bita Darvish Rouhani, and Farinaz Koushanfar","author":"Chen Huili","year":"2019","unstructured":"Huili Chen, Bita Darvish Rouhani, and Farinaz Koushanfar. 2019. Blackmarks: Blackbox multibit watermarking for deep neural networks. arXiv preprint arXiv:1904.00344 (2019)."},{"key":"e_1_3_2_2_7_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.3390\/e22121379"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1117\/1.1494075"},{"key":"e_1_3_2_2_10_1","volume-title":"DiffusionShield: AWatermark for Copyright Protection against Generative Diffusion Models. arXiv preprint arXiv:2306.04642","author":"Cui Yingqian","year":"2023","unstructured":"Yingqian Cui, Jie Ren, Han Xu, Pengfei He, Hui Liu, Lichao Sun, and Jiliang Tang. 2023. DiffusionShield: AWatermark for Copyright Protection against Generative Diffusion Models. arXiv preprint arXiv:2306.04642 (2023)."},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"e_1_3_2_2_12_1","first-page":"8780","article-title":"Diffusion models beat gans on image synthesis","volume":"34","author":"Dhariwal Prafulla","year":"2021","unstructured":"Prafulla Dhariwal and Alexander Nichol. 2021. Diffusion models beat gans on image synthesis. Advances in NeurIPS 34 (2021), 8780--8794.","journal-title":"Advances in NeurIPS"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"crossref","unstructured":"Patrick Esser Robin Rombach and Bjorn Ommer. 2021. Taming transformers for high-resolution image synthesis. In CVPR. 12873--12883.","DOI":"10.1109\/CVPR46437.2021.01268"},{"key":"e_1_3_2_2_14_1","volume-title":"Kam Woh Ng, and Chee Seng Chan","author":"Fan Lixin","year":"2019","unstructured":"Lixin Fan, Kam Woh Ng, and Chee Seng Chan. 2019. Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/WIFS55849.2022.9975409"},{"key":"e_1_3_2_2_16_1","volume-title":"The stable signature: Rooting watermarks in latent diffusion models. arXiv preprint arXiv:2303.15435","author":"Fernandez Pierre","year":"2023","unstructured":"Pierre Fernandez, Guillaume Couairon, Herv\u00e9 J\u00e9gou, Matthijs Douze, and Teddy Furon. 2023. The stable signature: Rooting watermarks in latent diffusion models. arXiv preprint arXiv:2303.15435 (2023)."},{"key":"e_1_3_2_2_17_1","volume-title":"Watermarking images in self-supervised latent spaces","author":"Fernandez Pierre","unstructured":"Pierre Fernandez, Alexandre Sablayrolles, Teddy Furon, Herv\u00e9 J\u00e9gou, and Matthijs Douze. 2022. Watermarking images in self-supervised latent spaces. In ICASSP. IEEE, 3054--3058."},{"key":"e_1_3_2_2_18_1","unstructured":"Matthew Gault. 2022. An AI-Generated Artwork Won First Place at a State Fair Fine Arts Competition and Artists Are Pissed. URL: https:\/\/www. vice. com\/en\/article\/bvmvqm\/an-aigenerated-artwork-won-first-place-at-a-statefair- fine-arts-competition-and-artists-are-pissed (2022)."},{"key":"e_1_3_2_2_19_1","unstructured":"Shuyang Gu Dong Chen Jianmin Bao FangWen Bo Zhang Dongdong Chen Lu Yuan and Baining Guo. 2022. Vector quantized diffusion model for text-to-image synthesis. In CVPR. 10696--10706."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_2_21_1","volume-title":"Evolutionary trigger set generation for dnn black-box watermarking. arXiv preprint arXiv:1906.04411","author":"Guo Jia","year":"2019","unstructured":"Jia Guo and Miodrag Potkonjak. 2019. Evolutionary trigger set generation for dnn black-box watermarking. arXiv preprint arXiv:1906.04411 (2019)."},{"key":"e_1_3_2_2_22_1","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. Advances in NeurIPS 33 (2020), 6840--6851.","journal-title":"Advances in NeurIPS"},{"key":"e_1_3_2_2_23_1","volume-title":"Classifier-Free Diffusion Guidance. In NeurIPS 2021 Workshop.","author":"Ho Jonathan","year":"2021","unstructured":"Jonathan Ho and Tim Salimans. 2021. Classifier-Free Diffusion Guidance. In NeurIPS 2021 Workshop."},{"key":"e_1_3_2_2_24_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Jia Hengrui","year":"2021","unstructured":"Hengrui Jia, Christopher A Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot. 2021. Entangled watermarks as a defense against model extraction. In 30th USENIX Security Symposium (USENIX Security 21). 1937--1954."},{"key":"e_1_3_2_2_25_1","volume-title":"Evading Watermark based Detection of AI-Generated Content. arXiv preprint arXiv:2305.03807","author":"Jiang Zhengyuan","year":"2023","unstructured":"Zhengyuan Jiang, Jinghuai Zhang, and Neil Zhenqiang Gong. 2023. Evading Watermark based Detection of AI-Generated Content. arXiv preprint arXiv:2305.03807 (2023)."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"e_1_3_2_2_27_1","volume-title":"Denoising diffusion restoration models. arXiv preprint arXiv:2201.11793","author":"Kawar Bahjat","year":"2022","unstructured":"Bahjat Kawar, Michael Elad, Stefano Ermon, and Jiaming Song. 2022. Denoising diffusion restoration models. arXiv preprint arXiv:2201.11793 (2022)."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00582"},{"key":"e_1_3_2_2_29_1","volume-title":"Dongsoo Lee, Wanmo Kang, and Il- Chul Moon.","author":"Kim Dongjun","year":"2022","unstructured":"Dongjun Kim, Byeonghu Na, Se Jung Kwon, Dongsoo Lee, Wanmo Kang, and Il- Chul Moon. 2022. Maximum Likelihood Training of Implicit Nonlinear Diffusion Models. arXiv preprint arXiv:2205.13699 (2022)."},{"key":"e_1_3_2_2_30_1","first-page":"21696","article-title":"Variational diffusion models","volume":"34","author":"Kingma Diederik","year":"2021","unstructured":"Diederik Kingma, Tim Salimans, Ben Poole, and Jonathan Ho. 2021. Variational diffusion models. Advances in NeurIPS 34 (2021), 21696--21707.","journal-title":"Advances in NeurIPS"},{"key":"e_1_3_2_2_31_1","unstructured":"Varsha Kishore Xiangyu Chen Yan Wang Boyi Li and Kilian Q Weinberger. 2021. Fixed neural network steganography: Train the images not the network. In ICLR."},{"key":"e_1_3_2_2_32_1","volume-title":"BlindNet backdoor: Attack on deep neural network using blind watermark. Multimedia Tools and Applications","author":"Kwon Hyun","year":"2022","unstructured":"Hyun Kwon and Yongchul Kim. 2022. BlindNet backdoor: Attack on deep neural network using blind watermark. Multimedia Tools and Applications (2022), 1--18."},{"key":"e_1_3_2_2_33_1","volume-title":"Persistent and unforgeable watermarks for deep neural networks. arXiv preprint arXiv:1910.01226","author":"Li Huiying","year":"2019","unstructured":"Huiying Li, Emily Willson, Haitao Zheng, and Ben Y Zhao. 2019. Persistent and unforgeable watermarks for deep neural networks. arXiv preprint arXiv:1910.01226 (2019)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.103004"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.07.051"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359801"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"crossref","unstructured":"Tsung-Yi Lin Michael Maire Serge Belongie James Hays Pietro Perona Deva Ramanan Piotr Doll\u00e1r and C Lawrence Zitnick. 2014. Microsoft coco: Common objects in context. In roceedings of the European conference on computer vision (ECCV). 740--755.","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"e_1_3_2_2_38_1","volume-title":"Pseudo numerical methods for diffusion models on manifolds. arXiv preprint arXiv:2202.09778","author":"Liu Luping","year":"2022","unstructured":"Luping Liu, Yi Ren, Zhijie Lin, and Zhou Zhao. 2022. Pseudo numerical methods for diffusion models on manifolds. arXiv preprint arXiv:2202.09778 (2022)."},{"key":"e_1_3_2_2_39_1","volume-title":"Samaneh Azadi, Gong Zhang, Arman Chopikyan, Yuxiao Hu, Humphrey Shi, Anna Rohrbach, and Trevor Darrell.","author":"Liu Xihui","year":"2021","unstructured":"Xihui Liu, Dong Huk Park, Samaneh Azadi, Gong Zhang, Arman Chopikyan, Yuxiao Hu, Humphrey Shi, Anna Rohrbach, and Trevor Darrell. 2021. More control for free! image synthesis with semantic diffusion guidance. arXiv preprint arXiv:2112.05744 (2021)."},{"key":"e_1_3_2_2_40_1","volume-title":"International Conference on Learning Representations.","author":"Lukas Nils","year":"2020","unstructured":"Nils Lukas, Yuxuan Zhang, and Florian Kerschbaum. 2020. Deep Neural Network Fingerprinting by Conferrable Adversarial Examples. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i5.28210"},{"key":"e_1_3_2_2_42_1","volume-title":"Proceedings of the 29th International Conference on Computational Linguistics. 1801--1812","author":"Ma Zhiyuan","year":"2022","unstructured":"Zhiyuan Ma, Jianjun Li, Guohui Li, and Yongjing Cheng. 2022. GLAF: globalto- local aggregation and fission network for semantic level fact verification. In Proceedings of the 29th International Conference on Computational Linguistics. 1801--1812."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-long.9"},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548292"},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.174"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i11.26569"},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i5.28209"},{"key":"e_1_3_2_2_48_1","volume-title":"Neural Residual Diffusion Models for Deep Scalable Vision Generation. arXiv preprint arXiv:2406.13215","author":"Ma Zhiyuan","year":"2024","unstructured":"Zhiyuan Ma, Liangliang Zhao, Biqing Qi, and Bowen Zhou. 2024. Neural Residual Diffusion Models for Deep Scalable Vision Generation. arXiv preprint arXiv:2406.13215 (2024)."},{"key":"e_1_3_2_2_49_1","volume-title":"SDEdit: Guided Image Synthesis and Editing with Stochastic Differential Equations. In International Conference on Learning Representations.","author":"Meng Chenlin","year":"2021","unstructured":"Chenlin Meng, Yutong He, Yang Song, Jiaming Song, JiajunWu, Jun-Yan Zhu, and Stefano Ermon. 2021. SDEdit: Guided Image Synthesis and Editing with Stochastic Differential Equations. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00585"},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329808"},{"key":"e_1_3_2_2_52_1","volume-title":"Glide: Towards photorealistic image generation and editing with text-guided diffusion models. arXiv preprint arXiv:2112.10741","author":"Nichol Alex","year":"2021","unstructured":"Alex Nichol, Prafulla Dhariwal, Aditya Ramesh, Pranav Shyam, Pamela Mishkin, Bob McGrew, Ilya Sutskever, and Mark Chen. 2021. Glide: Towards photorealistic image generation and editing with text-guided diffusion models. arXiv preprint arXiv:2112.10741 (2021)."},{"key":"e_1_3_2_2_53_1","unstructured":"Alexander Quinn Nichol and Prafulla Dhariwal. 2021. Improved denoising diffusion probabilistic models. In ICML. 8162--8171."},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00363"},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01224"},{"key":"e_1_3_2_2_56_1","volume-title":"Investigating Deep Watermark Security: An Adversarial Transferability Perspective. arXiv preprint arXiv:2402.16397","author":"Qi Biqing","year":"2024","unstructured":"Biqing Qi, Junqi Gao, Yiang Luo, Jianxing Liu, Ligang Wu, and Bowen Zhou. 2024. Investigating Deep Watermark Security: An Adversarial Transferability Perspective. arXiv preprint arXiv:2402.16397 (2024)."},{"key":"e_1_3_2_2_57_1","volume-title":"Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, et al.","author":"Radford Alec","year":"2021","unstructured":"Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, et al. 2021. Learning transferable visual models from natural language supervision. In ICML. 8748--8763."},{"key":"e_1_3_2_2_58_1","volume-title":"Hierarchical text-conditional image generation with clip latents. arXiv preprint arXiv:2204.06125","author":"Ramesh Aditya","year":"2022","unstructured":"Aditya Ramesh, Prafulla Dhariwal, Alex Nichol, Casey Chu, and Mark Chen. 2022. Hierarchical text-conditional image generation with clip latents. arXiv preprint arXiv:2204.06125 (2022)."},{"key":"e_1_3_2_2_59_1","doi-asserted-by":"crossref","unstructured":"Robin Rombach Andreas Blattmann Dominik Lorenz Patrick Esser and Bj\u00f6rn Ommer. 2022. High-resolution image synthesis with latent diffusion models. In CVPR. 10684--10695.","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02155"},{"key":"e_1_3_2_2_61_1","volume-title":"Burcu Karagol Ayan, S Sara Mahdavi, Rapha Gontijo Lopes, et al.","author":"Saharia Chitwan","year":"2022","unstructured":"Chitwan Saharia, William Chan, Saurabh Saxena, Lala Li, Jay Whang, Emily Denton, Seyed Kamyar Seyed Ghasemipour, Burcu Karagol Ayan, S Sara Mahdavi, Rapha Gontijo Lopes, et al. 2022. Photorealistic Text-to-Image Diffusion Models with Deep Language Understanding. arXiv preprint arXiv:2205.11487 (2022)."},{"key":"e_1_3_2_2_62_1","volume-title":"Denoising diffusion implicit models. arXiv preprint arXiv:2010.02502","author":"Song Jiaming","year":"2020","unstructured":"Jiaming Song, Chenlin Meng, and Stefano Ermon. 2020. Denoising diffusion implicit models. arXiv preprint arXiv:2010.02502 (2020)."},{"key":"e_1_3_2_2_63_1","first-page":"1415","article-title":"Maximum likelihood training of score-based diffusion models","volume":"34","author":"Song Yang","year":"2021","unstructured":"Yang Song, Conor Durkan, Iain Murray, and Stefano Ermon. 2021. Maximum likelihood training of score-based diffusion models. Advances in NeurIPS 34 (2021), 1415--1428.","journal-title":"Advances in NeurIPS"},{"key":"e_1_3_2_2_64_1","volume-title":"Score-based generative modeling through stochastic differential equations. arXiv preprint arXiv:2011.13456","author":"Song Yang","year":"2020","unstructured":"Yang Song, Jascha Sohl-Dickstein, Diederik P Kingma, Abhishek Kumar, Stefano Ermon, and Ben Poole. 2020. Score-based generative modeling through stochastic differential equations. arXiv preprint arXiv:2011.13456 (2020)."},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475591"},{"key":"e_1_3_2_2_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9413062"},{"key":"e_1_3_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"e_1_3_2_2_68_1","first-page":"11287","article-title":"Score-based generative modeling in latent space","volume":"34","author":"Vahdat Arash","year":"2021","unstructured":"Arash Vahdat, Karsten Kreis, and Jan Kautz. 2021. Score-based generative modeling in latent space. Advances in NeurIPS 34 (2021), 11287--11302.","journal-title":"Advances in NeurIPS"},{"key":"e_1_3_2_2_69_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6085"},{"key":"e_1_3_2_2_70_1","first-page":"22","article-title":"Watermarking in deep neural networks via error back-propagation","volume":"2020","author":"Wang Jiangfeng","year":"2020","unstructured":"Jiangfeng Wang, Hanzhou Wu, Xinpeng Zhang, and Yuwei Yao. 2020. Watermarking in deep neural networks via error back-propagation. Electronic Imaging 2020, 4 (2020), 22--1.","journal-title":"Electronic Imaging"},{"key":"e_1_3_2_2_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8682202"},{"key":"e_1_3_2_2_72_1","volume-title":"Robust and undetectable whitebox watermarks for deep neural networks. arXiv preprint arXiv:1910.14268 1, 2","author":"Wang Tianhao","year":"2019","unstructured":"Tianhao Wang and Florian Kerschbaum. 2019. Robust and undetectable whitebox watermarks for deep neural networks. arXiv preprint arXiv:1910.14268 1, 2 (2019)."},{"key":"e_1_3_2_2_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.3030671"},{"key":"e_1_3_2_2_74_1","volume-title":"Lsun: Construction of a large-scale image dataset using deep learning with humans in the loop. arXiv preprint arXiv:1506.03365","author":"Yu Fisher","year":"2015","unstructured":"Fisher Yu, Ari Seff, Yinda Zhang, Shuran Song, Thomas Funkhouser, and Jianxiong Xiao. 2015. Lsun: Construction of a large-scale image dataset using deep learning with humans in the loop. arXiv preprint arXiv:1506.03365 (2015)."},{"key":"e_1_3_2_2_75_1","volume-title":"Thang Luong, Gunjan Baid, Zirui Wang, Vijay Vasudevan, Alexander Ku, Yinfei Yang, Burcu Karagol Ayan, et al.","author":"Yu Jiahui","year":"2022","unstructured":"Jiahui Yu, Yuanzhong Xu, Jing Yu Koh, Thang Luong, Gunjan Baid, Zirui Wang, Vijay Vasudevan, Alexander Ku, Yinfei Yang, Burcu Karagol Ayan, et al. 2022. Scaling autoregressive models for content-rich text-to-image generation. arXiv preprint arXiv:2206.10789 (2022)."},{"key":"e_1_3_2_2_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01418"},{"key":"e_1_3_2_2_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"e_1_3_2_2_78_1","volume-title":"Adding conditional control to text-to-image diffusion models. arXiv preprint arXiv:2302.05543","author":"Zhang Lvmin","year":"2023","unstructured":"Lvmin Zhang and Maneesh Agrawala. 2023. Adding conditional control to text-to-image diffusion models. arXiv preprint arXiv:2302.05543 (2023)."},{"key":"e_1_3_2_2_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISDFS52919.2021.9486352"},{"key":"e_1_3_2_2_80_1","volume-title":"A recipe for watermarking diffusion models. arXiv preprint arXiv:2303.10137","author":"Zhao Yunqing","year":"2023","unstructured":"Yunqing Zhao, Tianyu Pang, Chao Du, Xiao Yang, Ngai-Man Cheung, and Min Lin. 2023. A recipe for watermarking diffusion models. arXiv preprint arXiv:2303.10137 (2023)."},{"key":"e_1_3_2_2_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01267-0_40"}],"event":{"name":"MM '24: The 32nd ACM International Conference on Multimedia","location":"Melbourne VIC Australia","acronym":"MM '24","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 32nd ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664647.3681418","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664647.3681418","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:57:46Z","timestamp":1750294666000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664647.3681418"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,28]]},"references-count":81,"alternative-id":["10.1145\/3664647.3681418","10.1145\/3664647"],"URL":"https:\/\/doi.org\/10.1145\/3664647.3681418","relation":{},"subject":[],"published":{"date-parts":[[2024,10,28]]},"assertion":[{"value":"2024-10-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}