{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,17]],"date-time":"2026-02-17T19:24:53Z","timestamp":1771356293870,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","funder":[{"DOI":"10.13039\/100020595","name":"National Science and Technology Council","doi-asserted-by":"publisher","award":["114-2634-F-001-001-MBK,113-2634-F-002-007,112-2222-E-001-001-MY2"],"award-info":[{"award-number":["114-2634-F-001-001-MBK,113-2634-F-002-007,112-2222-E-001-001-MY2"]}],"id":[{"id":"10.13039\/100020595","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001869","name":"Academia Sinica","doi-asserted-by":"publisher","award":["AS-CDA-110-M09,AS-IAIA-114-M08"],"award-info":[{"award-number":["AS-CDA-110-M09,AS-IAIA-114-M08"]}],"id":[{"id":"10.13039\/501100001869","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,13]]},"DOI":"10.1145\/3733799.3762985","type":"proceedings-article","created":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T11:38:49Z","timestamp":1767094729000},"page":"276-286","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing Robustness in Post-Processing Watermarking: An Ensemble Attack Network Using CNNs and Transformers"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-1684-2564","authenticated-orcid":false,"given":"Tzuhsuan","family":"Huang","sequence":"first","affiliation":[{"name":"Academia Sinica, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8474-6140","authenticated-orcid":false,"given":"Cheng Yu","family":"Yeo","sequence":"additional","affiliation":[{"name":"National Yang Ming Chiao Tung University, Hsinchu, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1586-3594","authenticated-orcid":false,"given":"Tsai-Ling","family":"Huang","sequence":"additional","affiliation":[{"name":"National Yang Ming Chiao Tung University, Hsinchu, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2216-077X","authenticated-orcid":false,"given":"Hong-Han","family":"Shuai","sequence":"additional","affiliation":[{"name":"National Yang Ming Chiao Tung University, Hsinchu, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4662-7875","authenticated-orcid":false,"given":"Wen-Huang","family":"Cheng","sequence":"additional","affiliation":[{"name":"National Taiwan University, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0209-8932","authenticated-orcid":false,"given":"Jun-Cheng","family":"Chen","sequence":"additional","affiliation":[{"name":"Academia Sinica, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,12,30]]},"reference":[{"key":"e_1_3_3_1_2_2","unstructured":"Kristy Choi Kedar Tatwawadi Tsachy Weissman and Stefano Ermon. \u201cNecst: Neural joint source-channel coding.\u201d International Conference on Machine Learning 2018"},{"key":"e_1_3_3_1_3_2","doi-asserted-by":"crossref","unstructured":"Xiyang Luo Ruohan Zhan Huiwen Chang Feng Yang and Peyman Milanfar. \u201cDistortion agnostic deep watermarking \u201d Computer Vision and Pattern Recognition 2020","DOI":"10.1109\/CVPR42600.2020.01356"},{"key":"e_1_3_3_1_4_2","doi-asserted-by":"crossref","unstructured":"Tero Karras Samuli Laine Miika Aittala Janne Hellsten Jaakko Lehtinen and Timo Aila. \u201cAnalyzing and Improving the Image Quality of StyleGAN \u201d Computer Vision and Pattern Recognition 2020","DOI":"10.1109\/CVPR42600.2020.00813"},{"key":"e_1_3_3_1_5_2","unstructured":"Tero Karras Miika Aittala Samuli Laine Erik H\u00e4rk\u00f6nen Janwatermarkingne Hellsten Jaakko Lehtinen and Timo Aila. \u201cAlias-Free Generative Adversarial Networks \u201d Neural Information Processing Systems 2021"},{"key":"e_1_3_3_1_6_2","unstructured":"Ning Yu Guilin Liu Aysegul Dundar Andrew Tao Bryan Catanzaro Larry Davis and Mario Fritz. \u201cDual Contrastive Loss and Attention for GANs \u201d International Conference on Computer Vision 2021"},{"key":"e_1_3_3_1_7_2","unstructured":"Ning Yu Ke Li Peng Zhou Jitendra Malik Larry Davis and Mario Fritz. \u201cInclusive GAN: Improving Data and Minority Coverage in Generative Models \u201d European Conference on Computer Vision 2020"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"crossref","unstructured":"Ming Tao Hao Tang Fei Wu Xiao-Yuan Jing Bing-Kun Bao and Changsheng Xu. \u201cDF-GAN: A Simple and Effective Baseline for Text-to-Image Synthesis \u201d Computer Vision and Pattern Recognition 2022","DOI":"10.1109\/CVPR52688.2022.01602"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"crossref","unstructured":"Yufan Zhou Ruiyi Zhang Changyou Chen Chunyuan Li Chris Tensmeyer Tong Yu Jiuxiang Gu Jinhui Xu and Tong Sun. \u201cLAFITE: Towards Language-Free Training for Text-to-Image Generation \u201d Computer Vision and Pattern Recognition 2022","DOI":"10.1109\/CVPR52688.2022.01738"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"crossref","unstructured":"Minguk Kang Jun-Yan Zhu Richard Zhang Jaesik Park Eli Shechtman Sylvain Paris and Taesung Park. \u201cScaling up GANs for Text-to-Image Synthesis \u201d Computer Vision and Pattern Recognition 2023","DOI":"10.1109\/CVPR52729.2023.00976"},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"crossref","unstructured":"Yujun Shen Jinjin Gu Xiaoou Tang and Bolei Zhou. \u201cInterpreting the Latent Space of GANs for Semantic Face Editing \u201d Computer Vision and Pattern Recognition 2020","DOI":"10.1109\/CVPR42600.2020.00926"},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"crossref","unstructured":"Hamza Pehlivan Yusuf Dalva and Aysegul Dundar. \u201cStyleRes: Transforming the Residuals for Real Image Editing with StyleGAN \u201d Computer Vision and Pattern Recognition 2023","DOI":"10.1109\/CVPR52729.2023.00182"},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"crossref","unstructured":"Maomao Li Ge Yuan Cairong Wang Zhian Liu Yong Zhang Yongwei Nie Jue Wang and Dong Xu. \u201cE4S: Fine-grained Face Swapping via Editing With Regional GAN Inversion \u201d Computer Vision and Pattern Recognition 2023","DOI":"10.1109\/CVPR52729.2023.00829"},{"key":"e_1_3_3_1_14_2","unstructured":"Tero Karras Miika Aittala Timo Aila and Samuli Laine. \u201cElucidating the Design Space of Diffusion-Based Generative Models \u201d Neural Information Processing Systems 2022"},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"crossref","unstructured":"Tim Brooks Aleksander Holynski and Alexei A. Efros. \u201cInstructPix2Pix: Learning to Follow Image Editing Instructions \u201d Computer Vision and Pattern Recognition 2023","DOI":"10.1109\/CVPR52729.2023.01764"},{"key":"e_1_3_3_1_16_2","unstructured":"Alex Nichol Prafulla Dhariwal Aditya Ramesh Pranav Shyam Pamela Mishkin Bob McGrew Ilya Sutskever and Mark Chen. \u201cGLIDE: Towards Photorealistic Image Generation and Editing with Text-Guided Diffusion Models \u201d International Conference on Machine Learning 2022"},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"crossref","unstructured":"Lvmin Zhang Anyi Rao and Maneesh Agrawala. \u201cAdding Conditional Control to Text-to-Image Diffusion Models \u201d International Conference on Machine Learning 2023","DOI":"10.1109\/ICCV51070.2023.00355"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"crossref","unstructured":"Jiren Zhu Russell Kaplan Justin Johnson and Li Fei-Fei. \u201cHidden: Hiding data with deep networks \u201d European Conference on Computer Vision 2018","DOI":"10.1007\/978-3-030-01267-0_40"},{"key":"e_1_3_3_1_19_2","unstructured":"Bang An Mucong Ding Tahseen Rabbani Aakriti Agrawal Yuancheng Xu Chenghao Deng Sicheng Zhu Abdirisak Mohamed Yuxin Wen Tom Goldstein and Furong Huang. \u201cWAVES: Benchmarking the Robustness of Image Watermarks \u201d International Conference on Machine Learning 2024"},{"key":"e_1_3_3_1_20_2","doi-asserted-by":"crossref","unstructured":"Matthew Tancik Ben Mildenhall and Ren Ng. \u201cStegaStamp: Invisible Hyperlinks in Physical Photographs \u201d Computer Vision and Pattern Recognition 2020","DOI":"10.1109\/CVPR42600.2020.00219"},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"crossref","unstructured":"Pierre Fernandez Guillaume Couairon Herv\u00e9 J\u00e9gou Matthijs Douze and Teddy Furon. \u201cThe Stable Signature: Rooting Watermarks in Latent Diffusion Models \u201d International Conference on Computer Vision 2023","DOI":"10.1109\/ICCV51070.2023.02053"},{"key":"e_1_3_3_1_22_2","unstructured":"Junxiong Lu Jiangqun Ni Wenkang Su and Hao Xie. \u201cWavelet-Based CNN for Robust and High-Capacity Image Watermarking \u201d IEEE International Conference on Multimedia and Expo 2022"},{"key":"e_1_3_3_1_23_2","unstructured":"Ning Yu Vladislav Skripniuk Sahar Abdelnabi and Mario Fritz. \u201cArtificial Fingerprinting for Generative Models: Rooting Deepfake Attribution in Training Data \u201d Computer Vision and Pattern Recognition 2021"},{"key":"e_1_3_3_1_24_2","unstructured":"Yunqing Zhao Tianyu Pang Chao Du Xiao Yang Ngai-Man Cheung and Min Lin. \u201cA Recipe for Watermarking Diffusion Models \u201d arXiv preprint 2023"},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"crossref","unstructured":"Robin Rombach Andreas Blattmann Dominik Lorenz Patrick Esser and Bj\u00f6rn Ommer. \u201cHigh-Resolution Image Synthesis with Latent Diffusion Models \u201d Computer Vision and Pattern Recognition 2022","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_3_1_26_2","unstructured":"Yuxin Wen John Kirchenbauer Jonas Geiping and Tom Goldstein. \u201cTree-Ring Watermarks: Fingerprints for Diffusion Images that are Invisible and Robust \u201d Neural Information Processing Systems 2023"},{"key":"e_1_3_3_1_27_2","unstructured":"Changhoon Kim Kyle Min Maitreya Patel Sheng Cheng and Yezhou Yang. \u201cWOUAF: Weight Modulation for User Attribution and Fingerprinting in Text-to-Image Diffusion Models \u201d Computer Vision and Pattern Recognition 2024"},{"key":"e_1_3_3_1_28_2","unstructured":"Nils Lukas and Florian Kerschbaum. \u201cPTW: Pivotal Tuning Watermarking for Pre-Trained Image Generators \u201d USENIX: The Advanced Computing Systems Association 2023"},{"key":"e_1_3_3_1_29_2","unstructured":"Alexey Dosovitskiy Lucas Beyer Alexander Kolesnikov Dirk Weissenborn Xiaohua Zhai Thomas Unterthiner Mostafa Dehghani Matthias Minderer Georg Heigold Sylvain Gelly Jakob Uszkoreit and Neil Houlsby. \u201cAn Image is Worth 16x16 Words: Transformers for Image Recognition at Scale \u201d International Conference on Learning Representations 2021"},{"key":"e_1_3_3_1_30_2","unstructured":"Maithra Raghu Thomas Unterthiner Simon Kornblith Chiyuan Zhang and Alexey Dosovitskiy. \u201cDo Vision Transformers See Like Convolutional Neural Networks? \u201d Neural Information Processing Systems 2021"},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"crossref","unstructured":"Ziwei Liu Ping Luo Xiaogang Wang and Xiaoou Tang. \u201cDeep Learning Face Attributes in the Wild \u201d International Conference on Computer Vision 2015","DOI":"10.1109\/ICCV.2015.425"},{"key":"e_1_3_3_1_32_2","unstructured":"Tsung-Yi Lin Michael Maire Serge Belongie Lubomir Bourdev Ross Girshick James Hays Pietro Perona Deva Ramanan C. Lawrence Zitnick and Piotr Doll\u00e1r. \u201cMicrosoft COCO: Common Objects in Context \u201d European Conference on Computer Vision 2014"},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"crossref","unstructured":"Han Fang Zhaoyang Jia Hang Zhou Zehua Ma and Weiming Zhang. \u201cEncoded Feature Enhancement in Watermarking Network for Distortion in Real Scenes \u201d IEEE TRANSACTIONS on MULTIMEDIA 2023","DOI":"10.1109\/TMM.2022.3149641"},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"crossref","unstructured":"Chuan Qin XIaomeng Li Zhenyi Zhang Fengyong Li Xinpeng Zhang and Guorui Feng. \u201cPrint-Camera Resistant Image Watermarking With Deep Noise Simulation and Constrained Learning \u201d IEEE TRANSACTIONS on MULTIMEDIA 2024","DOI":"10.1109\/TMM.2023.3293272"},{"key":"e_1_3_3_1_35_2","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. \u201cTowards Deep Learning Models Resistant to Adversarial Attacks \u201d International Conference on Learning Representations 2018"},{"key":"e_1_3_3_1_36_2","unstructured":"Kaiming He Xiangyu Zhang Shaoqing Ren and Jian Sun. \u201cDeep Residual Learning for Image Recognition \u201d Computer Vision and Pattern Recognition 2016"},{"key":"e_1_3_3_1_37_2","unstructured":"Alec Radford Jong Wook Kim Chris Hallacy Aditya Ramesh Gabriel Goh Sandhini Agarwal Girish Sastry Amanda Askell Pamela Mishkin Jack Clark Gretchen Krueger and Ilya Sutskever. \u201cLearning Transferable Visual Models From Natural Language Supervision \u201d International Conference on Machine Learning 2021"},{"key":"e_1_3_3_1_38_2","unstructured":"Dustin Podell Zion English Kyle Lacey Andreas Blattmann Tim Dockhorn Jonas M\u00fcller Joe Penna and Robin Rombach. \u201cSDXL: Improving Latent Diffusion Models for High-Resolution Image Synthesis \u201d arXiv preprint arXiv 2023"},{"key":"e_1_3_3_1_39_2","unstructured":"Mehrdad Saberi Vinu Sankar Sadasivan Keivan Rezaei Aounon Kumar Atoosa Chegini Wenxiao Wang and Soheil Feizi. \u201cRobustness of AI-Image Detectors: Fundamental Limits and Practical Attacks \u201d International Conference on Learning Representations 2023"},{"key":"e_1_3_3_1_40_2","unstructured":"Jinkun You and Yicong Zhou. \u201cTwo-Stage Watermark Removal Framework for Spread Spectrum Watermarking \u201d IEEE TRANSACTIONS on MULTIMEDIA 2024"},{"key":"e_1_3_3_1_41_2","unstructured":"Mingze He Hongxia Wang Fei Zhang and Yuyuan Xiang. \u201cExploring Accurate Invariants on Polar Harmonic Fourier Moments in Polar Coordinates for Robust Image Watermarking \u201d IEEE TRANSACTIONS on MULTIMEDIA 2023"},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"crossref","unstructured":"Han Fang Zhaoyang Jia Yupeng Qiu Jiyi Zhang Weiming Zhang and Ee-Chien Chang. \u201cDe-END: Decoder-Driven Watermarking Network \u201d IEEE TRANSACTIONS on MULTIMEDIA 2023","DOI":"10.1109\/TMM.2022.3223559"},{"key":"e_1_3_3_1_43_2","unstructured":"Jinkun You Yuan-Gen Wang Guopu Zhu Ligang Wu Hongli Zhang and Sam Kwong. \u201cEstimating the Secret Key of Spread Spectrum Watermarking Based on Equivalent Keys \u201d IEEE TRANSACTIONS on MULTIMEDIA 2023"},{"key":"e_1_3_3_1_44_2","doi-asserted-by":"crossref","unstructured":"Yu-Feng Chen Tzuhsuan Huang Pin-Yen Chiu and Jun-Cheng Chen. \u201cInvisible Backdoor Triggers in Image Editing Model via Deep Watermarking \u201d arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2506.04879 2025","DOI":"10.1109\/AVSS65446.2025.11149824"},{"key":"e_1_3_3_1_45_2","doi-asserted-by":"crossref","unstructured":"Jia Shuai and Ma Chao and Yao Taiping and Yin Bangjie and Ding Shouhong and Yang Xiaokang. \u201cExploring Frequency Adversarial Attacks for Face Forgery Detection \u201d Computer Vision and Pattern Recognition 2022","DOI":"10.1109\/CVPR52688.2022.00407"},{"key":"e_1_3_3_1_46_2","doi-asserted-by":"crossref","unstructured":"Luo Cheng and Lin Qinliang and Xie Weicheng and Wu Bizhu and Xie Jinheng and Shen Linlin. \u201cFrequency-driven Imperceptible Adversarial Attack on Semantic Similarity \u201d Computer Vision and Pattern Recognition 2022","DOI":"10.1109\/CVPR52688.2022.01488"}],"event":{"name":"AISec '25: Proceedings of the 2025 Workshop on Artificial Intelligence and Security","location":"Taipei , Taiwan","acronym":"AISec '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 18th ACM Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3733799.3762985","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,17]],"date-time":"2026-02-17T18:52:55Z","timestamp":1771354375000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3733799.3762985"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":45,"alternative-id":["10.1145\/3733799.3762985","10.1145\/3733799"],"URL":"https:\/\/doi.org\/10.1145\/3733799.3762985","relation":{},"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2025-12-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}