{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:54:21Z","timestamp":1781600061412,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":72,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T00:00:00Z","timestamp":1781568000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,17]]},"DOI":"10.1145\/3785353.3815095","type":"proceedings-article","created":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:11:30Z","timestamp":1781597490000},"page":"201-212","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Turning Distillation against Obfuscation: A Recovery Framework for DNN White-Box Watermarks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-7183-435X","authenticated-orcid":false,"given":"Mahdieh","family":"Pouresmaeil","sequence":"first","affiliation":[{"name":"data science departemant-Latim, IMT Atlantique, Brest, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1131-4115","authenticated-orcid":false,"given":"Reda","family":"Bellafqira","sequence":"additional","affiliation":[{"name":"data science departement-latim, IMT Atlantique, brest, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7689-4125","authenticated-orcid":false,"given":"Kassem","family":"Kallas","sequence":"additional","affiliation":[{"name":"latim, Inserm, brest, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1669-7140","authenticated-orcid":false,"given":"Gw\u00e9nol\u00e9","family":"Quellec","sequence":"additional","affiliation":[{"name":"latim, Inserm, brest, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5643-0224","authenticated-orcid":false,"given":"Gouenou","family":"Coatrieux","sequence":"additional","affiliation":[{"name":"data science departement-latim, IMT Atlantique, brest, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,16]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"Josh Achiam Steven Adler Sandhini Agarwal Lama Ahmad Ilge Akkaya Florencia\u00a0Leoni Aleman Diogo Almeida Janko Altenschmidt Sam Altman Shyamal Anadkat et\u00a0al. 2023. Gpt-4 technical report. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2303.08774 (2023)."},{"key":"e_1_3_3_2_3_2","first-page":"1615","volume-title":"27th USENIX security symposium (USENIX Security 18)","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX security symposium (USENIX Security 18). 1615\u20131631."},{"key":"e_1_3_3_2_4_2","unstructured":"Valentin Barbaza Alan\u00a0Rodrigo Diaz-Rizo Hassan Aboushady Spyridon Raptis and Haralampos-G Stratigopoulos. 2025. Stealing AI Model Weights Through Covert Communication Channels. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2510.00151 (2025)."},{"key":"e_1_3_3_2_5_2","unstructured":"Reda Bellafqira and Gouenou Coatrieux. 2022. Diction: Dynamic robust white box watermarking scheme. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2210.15745 (2022)."},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"crossref","unstructured":"Emili\u00a0Silva Bezerra Quefren\u00a0Oliveira Leher Uendel\u00a0Diego da Silva\u00a0Alves Thuanne Paix\u00e3o and Ana\u00a0Beatriz Alvarez. 2024. Deep generative AI based on denoising diffusion probabilistic models for applications in image processing. Interfases020 (2024) 71\u201393.","DOI":"10.26439\/interfases2024.n020.7389"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"crossref","unstructured":"Prajjwal Bhargava Aleksandr Drozd and Anna Rogers. 2021. Generalization in NLI: Ways (Not) To Go Beyond Simple Heuristics. arxiv:https:\/\/arXiv.org\/abs\/2110.01518\u00a0[cs.CL]","DOI":"10.18653\/v1\/2021.insights-1.18"},{"key":"e_1_3_3_2_8_2","unstructured":"Nicholas Carlini Daniel Paleka Krishnamurthy\u00a0Dj Dvijotham Thomas Steinke Jonathan Hayase A\u00a0Feder Cooper Katherine Lee Matthew Jagielski Milad Nasr Arthur Conmy et\u00a0al. 2024. Stealing part of a production language model. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2403.06634 (2024)."},{"key":"e_1_3_3_2_9_2","unstructured":"Huili Chen Bita\u00a0Darvish Rouhani and Farinaz Koushanfar. 2019. Blackmarks: Blackbox multibit watermarking for deep neural networks. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1904.00344 (2019)."},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"crossref","first-page":"485","DOI":"10.1145\/3297858.3304051","volume-title":"Proceedings of the twenty-fourth international conference on architectural support for programming languages and operating systems","author":"Darvish\u00a0Rouhani Bita","year":"2019","unstructured":"Bita Darvish\u00a0Rouhani, Huili Chen, and Farinaz Koushanfar. 2019. Deepsigns: An end-to-end watermarking framework for ownership protection of deep neural networks. In Proceedings of the twenty-fourth international conference on architectural support for programming languages and operating systems. 485\u2013497."},{"key":"e_1_3_3_2_11_2","first-page":"4171","volume-title":"Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers)","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. Bert: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). 4171\u20134186."},{"key":"e_1_3_3_2_12_2","unstructured":"Lixin Fan Kam\u00a0Woh Ng and Chee\u00a0Seng Chan. 2019. Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_3_2_13_2","unstructured":"Aaron Grattafiori Abhimanyu Dubey Abhinav Jauhri Abhinav Pandey Abhishek Kadian Ahmad Al-Dahle Aiesha Letman Akhil Mathur Alan Schelten Alex Vaughan et\u00a0al. 2024. The llama 3 herd of models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2407.21783 (2024)."},{"key":"e_1_3_3_2_14_2","unstructured":"Daya Guo Dejian Yang Haowei Zhang Junxiao Song Peiyi Wang Qihao Zhu Runxin Xu Ruoyu Zhang Shirong Ma Xiao Bi et\u00a0al. 2025. Deepseek-r1: Incentivizing reasoning capability in llms via reinforcement learning. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2501.12948 (2025)."},{"key":"e_1_3_3_2_15_2","series-title":"(IH&MMSEC \u201925)","first-page":"114","volume-title":"Proceedings of the 2025 ACM Workshop on Information Hiding and Multimedia Security","author":"Guo Shengnan","year":"2025","unstructured":"Shengnan Guo, Kaiyi Pang, Zhongliang Yang, Yamin Li, Yu Qing, and Yongfeng Huang. 2025. Reinforcement Learning-based Copyright Protection Watermarking for Large Language Model. In Proceedings of the 2025 ACM Workshop on Information Hiding and Multimedia Security(IH&MMSEC \u201925). Association for Computing Machinery, New York, NY, USA, 114\u2013120. 10.1145\/3733102.3733135"},{"key":"e_1_3_3_2_16_2","series-title":"(CVPR \u201916)","first-page":"770","volume-title":"Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. In Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition (Las Vegas, NV, USA) (CVPR \u201916). IEEE, 770\u2013778. 10.1109\/CVPR.2016.90"},{"key":"e_1_3_3_2_17_2","series-title":"(AAAI\u201919\/IAAI\u201919\/EAAI\u201919)","volume-title":"Proceedings of the Thirty-Third AAAI Conference on Artificial Intelligence and Thirty-First Innovative Applications of Artificial Intelligence Conference and Ninth AAAI Symposium on Educational Advances in Artificial Intelligence","author":"Heo Byeongho","year":"2019","unstructured":"Byeongho Heo, Minsik Lee, Sangdoo Yun, and Jin\u00a0Young Choi. 2019. Knowledge transfer via distillation of activation boundaries formed by hidden neurons. In Proceedings of the Thirty-Third AAAI Conference on Artificial Intelligence and Thirty-First Innovative Applications of Artificial Intelligence Conference and Ninth AAAI Symposium on Educational Advances in Artificial Intelligence (Honolulu, Hawaii, USA) (AAAI\u201919\/IAAI\u201919\/EAAI\u201919). AAAI Press, Article 464, 9\u00a0pages. 10.1609\/aaai.v33i01.33013779"},{"key":"e_1_3_3_2_18_2","unstructured":"Geoffrey\u00a0E. Hinton Oriol Vinyals and Jeffrey Dean. 2015. Distilling the Knowledge in a Neural Network. ArXiv abs\/1503.02531 (2015). https:\/\/api.semanticscholar.org\/CorpusID:7200347"},{"key":"e_1_3_3_2_19_2","series-title":"(NIPS \u201920)","volume-title":"Proceedings of the 34th International Conference on Neural Information Processing Systems","author":"Ho Jonathan","year":"2020","unstructured":"Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. In Proceedings of the 34th International Conference on Neural Information Processing Systems (Vancouver, BC, Canada) (NIPS \u201920). Curran Associates Inc., Red Hook, NY, USA, Article 574, 12\u00a0pages."},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","unstructured":"Guang Hua and Andrew Beng\u00a0Jin Teoh. 2023. Deep Fidelity in DNN Watermarking: A Study of Backdoor Watermarking for Classification Models. Pattern Recognition 144 (2023) 109844. 10.1016\/j.patcog.2023.109844","DOI":"10.1016\/j.patcog.2023.109844"},{"key":"e_1_3_3_2_21_2","doi-asserted-by":"publisher","unstructured":"Guang Hua Andrew Beng\u00a0Jin Teoh Yong Xiang and Hao Jiang. 2023. Unambiguous and High-Fidelity Backdoor Watermarking for Deep Neural Networks. IEEE Transactions on Neural Networks and Learning Systems (2023) 1\u201314. 10.1109\/TNNLS.2023.3250210","DOI":"10.1109\/TNNLS.2023.3250210"},{"key":"e_1_3_3_2_22_2","unstructured":"Zehao Huang and Naiyan Wang. 2017. Like what you like: Knowledge distill via neuron selectivity transfer. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1707.01219 (2017)."},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"crossref","first-page":"4163","DOI":"10.18653\/v1\/2020.findings-emnlp.372","volume-title":"Findings of the association for computational linguistics: EMNLP 2020","author":"Jiao Xiaoqi","year":"2020","unstructured":"Xiaoqi Jiao, Yichun Yin, Lifeng Shang, Xin Jiang, Xiao Chen, Linlin Li, Fang Wang, and Qun Liu. 2020. Tinybert: Distilling bert for natural language understanding. In Findings of the association for computational linguistics: EMNLP 2020. 4163\u20134174."},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/WIFS55849.2022.9975428"},{"key":"e_1_3_3_2_25_2","first-page":"1","volume-title":"ICASSP 2023-2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Kallas Kassem","year":"2023","unstructured":"Kassem Kallas and Teddy Furon. 2023. Mixer: Dnn watermarking using image mixup. In ICASSP 2023-2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 1\u20135."},{"key":"e_1_3_3_2_26_2","series-title":"(NIPS\u201918)","first-page":"2765","volume-title":"Proceedings of the 32nd International Conference on Neural Information Processing Systems","author":"Kim Jangho","year":"2018","unstructured":"Jangho Kim, SeongUk Park, and Nojun Kwak. 2018. Paraphrasing complex network: network compression via factor transfer. In Proceedings of the 32nd International Conference on Neural Information Processing Systems (Montr\u00e9al, Canada) (NIPS\u201918). Curran Associates Inc., Red Hook, NY, USA, 2765\u20132774."},{"key":"e_1_3_3_2_27_2","unstructured":"Diederik\u00a0P Kingma and Max Welling. 2013. Auto-encoding variational bayes. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1312.6114 (2013)."},{"key":"e_1_3_3_2_28_2","volume-title":"Learning Multiple Layers of Features from Tiny Images","author":"Krizhevsky Alex","year":"2009","unstructured":"Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images. Technical Report. University of Toronto."},{"key":"e_1_3_3_2_29_2","unstructured":"Pranjal Kumar. 2025. Diffusion Models and Generative Artificial Intelligence: Frameworks Applications and Challenges. Archives of Computational Methods in Engineering (2025) 1\u201344."},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1145\/3437880.3460402","volume-title":"Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security","author":"Kuribayashi Minoru","year":"2021","unstructured":"Minoru Kuribayashi, Takuro Tanaka, Shunta Suzuki, Tatsuya Yasui, and Nobuo Funabiki. 2021. White-box watermarking scheme for fully-connected layers in fine-tuning model. In Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security. 165\u2013170."},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"crossref","unstructured":"Minoru Kuribayashi Tatsuya Yasui and Asad Malik. 2023. White Box Watermarking for Convolution Layers in Fine-Tuning Model Using the Constant Weight Code. Journal of Imaging 9 6 (2023). https:\/\/www.mdpi.com\/2313-433X\/9\/6\/117","DOI":"10.3390\/jimaging9060117"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","unstructured":"Erwan Le\u00a0Merrer Patrick P\u00e9rez and Gilles Tr\u00e9dan. 2020. Adversarial Frontier Stitching for Remote Neural Network Watermarking. Neural Computing and Applications 32 13 (2020) 9233\u20139244. 10.1007\/s00521-019-04434-z","DOI":"10.1007\/s00521-019-04434-z"},{"key":"e_1_3_3_2_33_2","doi-asserted-by":"crossref","unstructured":"Chengyuan Li Tianyu Zhang Xusheng Du Ye Zhang and Haoran Xie. 2025. Generative AI models for different steps in architectural design: A literature review. Frontiers of Architectural Research 14 3 (2025) 759\u2013783.","DOI":"10.1016\/j.foar.2024.10.001"},{"key":"e_1_3_3_2_34_2","first-page":"3064","volume-title":"ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Li Guobiao","year":"2022","unstructured":"Guobiao Li, Sheng Li, Zhenxing Qian, and Xinpeng Zhang. 2022. Encryption Resistant Deep Neural Network Watermarking. In ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). 3064\u20133068. 10.1109\/ICASSP43922.2022.9746461"},{"key":"e_1_3_3_2_35_2","volume-title":"European Conference on Computer Vision (ECCV 2024)","author":"Li Yuxuan","year":"2024","unstructured":"Yuxuan Li et\u00a0al. 2024. Not Just Change the Labels, Learn the Features: Watermarking Deep Neural Networks with Multi-View Data. In European Conference on Computer Vision (ECCV 2024). Springer. 10.1007\/978-3-031-73650-6_16"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"crossref","unstructured":"Yue Li Benedetta Tondi and Mauro Barni. 2021. Spread-transform dither modulation watermarking of deep neural network. Journal of Information Security and Applications 63 (2021) 103004.","DOI":"10.1016\/j.jisa.2021.103004"},{"key":"e_1_3_3_2_37_2","first-page":"126","volume-title":"Proceedings of the 35th annual computer security applications conference","author":"Li Zheng","year":"2019","unstructured":"Zheng Li, Chengyu Hu, Yang Zhang, and Shanqing Guo. 2019. How to prove your model belongs to you: A blind-watermark based framework to protect intellectual property of DNN. In Proceedings of the 35th annual computer security applications conference. 126\u2013137."},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"crossref","first-page":"1231","DOI":"10.1145\/3634737.3657002","volume-title":"Proceedings of the 19th ACM Asia conference on computer and communications security","author":"Liang Jiacheng","year":"2024","unstructured":"Jiacheng Liang, Ren Pang, Changjiang Li, and Ting Wang. 2024. Model extraction attacks revisited. In Proceedings of the 19th ACM Asia conference on computer and communications security. 1231\u20131245."},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"crossref","unstructured":"Chang Liu Yinpeng Dong Wenzhao Xiang Xiao Yang Hang Su Jun Zhu Yuefeng Chen Yuan He Hui Xue and Shibao Zheng. 2025. A comprehensive study on robustness of image classification models: Benchmarking and rethinking. International Journal of Computer Vision 133 2 (2025) 567\u2013589.","DOI":"10.1007\/s11263-024-02196-3"},{"key":"e_1_3_3_2_40_2","first-page":"6978","volume-title":"ICML","author":"Liu Hanwen","year":"2021","unstructured":"Hanwen Liu, Zhenyu Weng, and Yuesheng Zhu. 2021. Watermarking Deep Neural Networks with Greedy Residuals.. In ICML , Vol.\u00a0139. 6978\u20136988."},{"key":"e_1_3_3_2_41_2","volume-title":"Proceedings of International Conference on Computer Vision (ICCV)","author":"Liu Ziwei","year":"2015","unstructured":"Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang. 2015. Deep Learning Face Attributes in the Wild. In Proceedings of International Conference on Computer Vision (ICCV)."},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"crossref","unstructured":"Peizhuo Lv Pan Li Shengzhi Zhang Kai Chen Ruigang Liang Hualong Ma Yue Zhao and Yingjiu Li. 2023. A robustness-assured white-box watermark in neural networks. IEEE Transactions on Dependable and Secure Computing 20 6 (2023) 5214\u20135229.","DOI":"10.1109\/TDSC.2023.3242737"},{"key":"e_1_3_3_2_43_2","volume-title":"Network and Distributed System Security Symposium (NDSS 2024)","author":"Lv Peizhuo","year":"2024","unstructured":"Peizhuo Lv, Pan Pan, Shuning Zhang, Yue Xie, et\u00a0al. 2024. SSL-WM: A Black-Box Watermarking Approach for Encoders Pre-trained by Self-supervised Learning. In Network and Distributed System Security Symposium (NDSS 2024)."},{"key":"e_1_3_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24374"},{"key":"e_1_3_3_2_45_2","volume-title":"TorchVision: PyTorch\u2019s Computer Vision library","author":"maintainers TorchVision","year":"2016","unstructured":"TorchVision maintainers and contributors. 2016. TorchVision: PyTorch\u2019s Computer Vision library."},{"key":"e_1_3_3_2_46_2","doi-asserted-by":"crossref","first-page":"228","DOI":"10.1145\/3321705.3329808","volume-title":"Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security","author":"Namba Ryota","year":"2019","unstructured":"Ryota Namba and Jun Sakuma. 2019. Robust watermarking of neural network with exponential weighting. In Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security. 228\u2013240."},{"key":"e_1_3_3_2_47_2","doi-asserted-by":"publisher","unstructured":"Xudong Pan Mi Zhang Yifan Yan Yining Wang and Min Yang. 2023. Cracking White-box DNN Watermarks via Invariant Neuron Transforms. (08 2023) 1783\u20131794. 10.1145\/3580305.3599291","DOI":"10.1145\/3580305.3599291"},{"key":"e_1_3_3_2_48_2","series-title":"(SEC \u201924)","volume-title":"Proceedings of the 33rd USENIX Conference on Security Symposium","author":"Pegoraro Alessandro","year":"2024","unstructured":"Alessandro Pegoraro, Carlotta Segna, Kavita Kumari, and Ahmad-Reza Sadeghi. 2024. DeepEclipse: how to break white-box DNN-watermarking schemes. In Proceedings of the 33rd USENIX Conference on Security Symposium (Philadelphia, PA, USA) (SEC \u201924). USENIX Association, USA, Article 296, 18\u00a0pages."},{"key":"e_1_3_3_2_49_2","volume-title":"3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings","author":"Romero Adriana","year":"2015","unstructured":"Adriana Romero, Nicolas Ballas, Samira\u00a0Ebrahimi Kahou, Antoine Chassang, Carlo Gatta, and Yoshua Bengio. 2015. FitNets: Hints for Thin Deep Nets. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1412.6550"},{"key":"e_1_3_3_2_50_2","doi-asserted-by":"crossref","unstructured":"KUMAR\u00a0GORAI SANJAY SARANGI ANURAG and PRADHAN SHEKHAR. 2025. DEEP LEARNING FOR IMAGE CLASSIFICATION: METHODS CHALLENGES AND FUTURE DIRECTIONS. INTERNATIONAL JOURNAL 11 1 (2025) 484\u2013496.","DOI":"10.32628\/CSEIT2511110"},{"key":"e_1_3_3_2_51_2","volume-title":"3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1409.1556"},{"key":"e_1_3_3_2_52_2","doi-asserted-by":"crossref","first-page":"1631","DOI":"10.18653\/v1\/D13-1170","volume-title":"Proceedings of the 2013 Conference on Empirical Methods in Natural Language Processing","author":"Socher Richard","year":"2013","unstructured":"Richard Socher, Alex Perelygin, Jean Wu, Jason Chuang, Christopher\u00a0D. Manning, Andrew Ng, and Christopher Potts. 2013. Recursive Deep Models for Semantic Compositionality Over a Sentiment Treebank. In Proceedings of the 2013 Conference on Empirical Methods in Natural Language Processing. Association for Computational Linguistics, Seattle, Washington, USA, 1631\u20131642. https:\/\/www.aclweb.org\/anthology\/D13-1170"},{"key":"e_1_3_3_2_53_2","doi-asserted-by":"crossref","unstructured":"Jiahao Sun Xiaodong Yang Shubai Chen Xin Qin and Bixiao Zeng. 2025. FedAWM: Adaptive Watermark Allocation in Non-IID Federated Learning. Knowledge-Based Systems (2025) 114938.","DOI":"10.1016\/j.knosys.2025.114938"},{"key":"e_1_3_3_2_54_2","doi-asserted-by":"publisher","unstructured":"Benedetta Tondi Andrea Costanzo and Mauro Barni. 2024. Robust and Large-Payload DNN Watermarking via Fixed Distribution-Optimized Weights. IEEE Transactions on Dependable and Secure Computing PP (01 2024) 1\u201317. 10.1109\/TDSC.2024.3426957","DOI":"10.1109\/TDSC.2024.3426957"},{"key":"e_1_3_3_2_55_2","unstructured":"Iulia Turc Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2019. Well-Read Students Learn Better: The Impact of Student Initialization on Knowledge Distillation. CoRR abs\/1908.08962 (2019). arXiv:https:\/\/arXiv.org\/abs\/1908.08962http:\/\/arxiv.org\/abs\/1908.08962"},{"key":"e_1_3_3_2_56_2","doi-asserted-by":"crossref","first-page":"269","DOI":"10.1145\/3078971.3078974","volume-title":"Proceedings of the 2017 ACM on international conference on multimedia retrieval","author":"Uchida Yusuke","year":"2017","unstructured":"Yusuke Uchida, Yuki Nagai, Shigeyuki Sakazawa, and Shin\u2019ichi Satoh. 2017. Embedding watermarks into deep neural networks. In Proceedings of the 2017 ACM on international conference on multimedia retrieval. 269\u2013277."},{"key":"e_1_3_3_2_57_2","volume-title":"IEEE Workshop on Information Forensics and Security","year":"2023","unstructured":"various. 2023. Mixer: A Black-box Watermarking Method for Training-phase Separation. In IEEE Workshop on Information Forensics and Security."},{"key":"e_1_3_3_2_58_2","volume-title":"AI Trustworthiness and Risk Assessment for Challenged Contexts Workshop (ATRACC), AAAI 2024 Fall Symposium","year":"2024","unstructured":"various. 2024. A Black-Box Watermarking Modulation for Object Detection Models. In AI Trustworthiness and Risk Assessment for Challenged Contexts Workshop (ATRACC), AAAI 2024 Fall Symposium."},{"key":"e_1_3_3_2_59_2","doi-asserted-by":"publisher","unstructured":"various. 2024. A Unique Identification-Oriented Black-Box Watermarking Scheme for Deep Classification Neural Networks. Symmetry 16 3 (2024) 299. 10.3390\/sym16030299","DOI":"10.3390\/sym16030299"},{"key":"e_1_3_3_2_60_2","unstructured":"various. 2025. NWaaS: Nonintrusive Watermarking as a Service for X-to-Image DNN. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2507.18036 (2025)."},{"key":"e_1_3_3_2_61_2","doi-asserted-by":"publisher","unstructured":"various. 2025. RoSe-Mix: A Robust and Secure DNN Watermarking Technique for Black-Box Settings. Machine Learning and Knowledge Extraction 7 (2025) 32. 10.3390\/make7010032","DOI":"10.3390\/make7010032"},{"key":"e_1_3_3_2_62_2","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan\u00a0N Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. Advances in neural information processing systems 30 (2017)."},{"key":"e_1_3_3_2_63_2","doi-asserted-by":"crossref","first-page":"993","DOI":"10.1145\/3442381.3450000","volume-title":"Proceedings of the web conference 2021","author":"Wang Tianhao","year":"2021","unstructured":"Tianhao Wang and Florian Kerschbaum. 2021. Riga: Covert and robust white-box watermarking of deep neural networks. In Proceedings of the web conference 2021. 993\u20131004."},{"key":"e_1_3_3_2_64_2","unstructured":"Chengcheng Wei Aoting Hu and Deiqing Yang. 2025. Practical Black-box Watermark Removal via Knowledge Distillation into Compact Models. (2025)."},{"key":"e_1_3_3_2_65_2","doi-asserted-by":"crossref","unstructured":"Rui Xin Chudi Zhong Zhi Chen Takuya Takagi Margo Seltzer and Cynthia Rudin. 2022. Exploring the whole rashomon set of sparse decision trees. Advances in neural information processing systems 35 (2022) 14071\u201314084.","DOI":"10.52202\/068431-1023"},{"key":"e_1_3_3_2_66_2","first-page":"2347","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Yan Yifan","year":"2023","unstructured":"Yifan Yan, Xudong Pan, Mi Zhang, and Min Yang. 2023. Rethinking { White-Box} watermarks on deep learning models under neural structural obfuscation. In 32nd USENIX Security Symposium (USENIX Security 23). 2347\u20132364."},{"key":"e_1_3_3_2_67_2","unstructured":"An Yang Anfeng Li Baosong Yang Beichen Zhang Binyuan Hui Bo Zheng Bowen Yu Chang Gao Chengen Huang Chenxu Lv et\u00a0al. 2025. Qwen3 technical report. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2505.09388 (2025)."},{"key":"e_1_3_3_2_68_2","doi-asserted-by":"crossref","unstructured":"Ali Yavari Tilman Schmoll Rainer\u00a0A Leitgeb Kim\u00a0Lien Huber Heiko Stino Andreas Pollreisz Wolfgang Drexler and Thomas Schlegl. 2026. Applicability study of AI attribution methods for ophthalmic image classification. Scientific Reports (2026).","DOI":"10.1038\/s41598-025-33120-5"},{"key":"e_1_3_3_2_69_2","first-page":"7130","volume-title":"2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Yim Junho","year":"2017","unstructured":"Junho Yim, Donggyu Joo, Jihoon Bae, and Junmo Kim. 2017. A Gift from Knowledge Distillation: Fast Optimization, Network Minimization and Transfer Learning. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 7130\u20137138. 10.1109\/CVPR.2017.754"},{"key":"e_1_3_3_2_70_2","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1145\/3196494.3196550","volume-title":"Proceedings of the 2018 on Asia conference on computer and communications security","author":"Zhang Jialong","year":"2018","unstructured":"Jialong Zhang, Zhongshu Gu, Jiyong Jang, Hui Wu, Marc\u00a0Ph Stoecklin, Heqing Huang, and Ian Molloy. 2018. Protecting intellectual property of deep neural networks with watermarking. In Proceedings of the 2018 on Asia conference on computer and communications security. 159\u2013172."},{"key":"e_1_3_3_2_71_2","unstructured":"Kaixiang Zhao Lincan Li Kaize Ding Neil\u00a0Zhenqiang Gong Yue Zhao and Yushun Dong. 2025. A systematic survey of model extraction attacks and defenses: State-of-the-art and perspectives. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2508.15031 (2025)."},{"key":"e_1_3_3_2_72_2","first-page":"382","volume-title":"2024 5th International Conference on Big Data & Artificial Intelligence & Software Engineering (ICBASE)","author":"Zheng Mingyang","year":"2024","unstructured":"Mingyang Zheng and Junling Ren. 2024. A high-load DNN watermarking scheme based on optimal embedding position. In 2024 5th International Conference on Big Data & Artificial Intelligence & Software Engineering (ICBASE). IEEE, 382\u2013387."},{"key":"e_1_3_3_2_73_2","doi-asserted-by":"crossref","first-page":"462","DOI":"10.1007\/978-3-030-47436-2_35","volume-title":"Advances in Knowledge Discovery and Data Mining: 24th Pacific-Asia Conference, PAKDD 2020, Singapore, May 11\u201314, 2020, Proceedings, Part II 24","author":"Zhong Qi","year":"2020","unstructured":"Qi Zhong, Leo\u00a0Yu Zhang, Jun Zhang, Longxiang Gao, and Yong Xiang. 2020. Protecting IP of deep neural networks with watermarking: A new label helps. In Advances in Knowledge Discovery and Data Mining: 24th Pacific-Asia Conference, PAKDD 2020, Singapore, May 11\u201314, 2020, Proceedings, Part II 24. Springer, 462\u2013474."}],"event":{"name":"IH&MMSec '26: ACM Workshop on Information Hiding and Multimedia Security","location":"Firenze Italy","acronym":"IH&MMSec '26","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 2026 ACM Workshop on Information Hiding and Multimedia Security"],"original-title":[],"deposited":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T08:14:14Z","timestamp":1781597654000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3785353.3815095"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,16]]},"references-count":72,"alternative-id":["10.1145\/3785353.3815095","10.1145\/3785353"],"URL":"https:\/\/doi.org\/10.1145\/3785353.3815095","relation":{},"subject":[],"published":{"date-parts":[[2026,6,16]]},"assertion":[{"value":"2026-06-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}