{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T15:57:31Z","timestamp":1781539051772,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":61,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T00:00:00Z","timestamp":1781481600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"State Key Laboratory of Cyberspace Security Defense","award":["E5D00311C3"],"award-info":[{"award-number":["E5D00311C3"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,16]]},"DOI":"10.1145\/3805622.3810742","type":"proceedings-article","created":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T14:42:57Z","timestamp":1781534577000},"page":"1936-1945","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["ComMark: Covert and Robust Black-Box Model Watermarking with Compressed Samples"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-0338-8528","authenticated-orcid":false,"given":"Yunfei","family":"Yang","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; State Key Laboratory of Cyberspace Security Defense, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0362-847X","authenticated-orcid":false,"given":"Xiaojun","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; State Key Laboratory of Cyberspace Security Defense, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0003-019X","authenticated-orcid":false,"given":"Zhendong","family":"Zhao","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; State Key Laboratory of Cyberspace Security Defense, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4188-9953","authenticated-orcid":false,"given":"Yu","family":"Zhou","sequence":"additional","affiliation":[{"name":"College of Computer Science, Nankai University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0673-0058","authenticated-orcid":false,"given":"Xiaoyan","family":"Gu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; State Key Laboratory of Cyberspace Security Defense, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7857-1546","authenticated-orcid":false,"given":"Juan","family":"Cao","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,15]]},"reference":[{"key":"e_1_3_3_1_2_2","first-page":"1615","volume-title":"27th USENIX security symposium (USENIX Security 18)","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX security symposium (USENIX Security 18). 1615\u20131631."},{"key":"e_1_3_3_1_3_2","doi-asserted-by":"crossref","unstructured":"Nasir Ahmed T_ Natarajan and Kamisetty\u00a0R Rao. 2006. Discrete cosine transform. IEEE transactions on Computers 100 1 (2006) 90\u201393.","DOI":"10.1109\/T-C.1974.223784"},{"key":"e_1_3_3_1_4_2","unstructured":"Muzhir\u00a0Shaban Al-Ani and Fouad\u00a0Hammadi Awad. 2013. The JPEG image compression algorithm. Int. J. Adv. Eng. Technol 6 3 (2013) 1055\u20131062."},{"key":"e_1_3_3_1_5_2","doi-asserted-by":"crossref","unstructured":"Abdulsalam Alkholidi Ayman Alfalou and Habib Hamam. 2007. A new approach for optical colored image compression using the JPEG standards. Signal Processing 87 4 (2007) 569\u2013583.","DOI":"10.1016\/j.sigpro.2006.06.011"},{"key":"e_1_3_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE55515.2023.00077"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00052"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i8.28664"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"crossref","unstructured":"Yihan Cao Siyu Li Yixin Liu Zhiling Yan Yutong Dai Philip Yu and Lichao Sun. 2025. A survey of ai-generated content (aigc). Comput. Surveys 57 5 (2025) 1\u201338.","DOI":"10.1145\/3704262"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"crossref","unstructured":"Chin-Chen Chang Tung-Shou Chen and Lou-Zo Chung. 2002. A steganographic method based upon JPEG and quantization table modification. Information Sciences 141 1-2 (2002) 123\u2013138.","DOI":"10.1016\/S0020-0255(01)00194-3"},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3323873.3325042"},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"crossref","unstructured":"Li Chen Penghao Wu Kashyap Chitta Bernhard Jaeger Andreas Geiger and Hongyang Li. 2024. End-to-end autonomous driving: Challenges and frontiers. IEEE Transactions on Pattern Analysis and Machine Intelligence (2024).","DOI":"10.1109\/TPAMI.2024.3435937"},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"crossref","unstructured":"Francisco\u00a0F Cunha Valentin Bl\u00fcml Lydia\u00a0M Zopf Andreas Walter Michael Wagner Wolfgang\u00a0J Weninger Lucas\u00a0A Thomaz Lu\u00eds\u00a0MN Tavora Luis\u00a0A da Silva\u00a0Cruz and Sergio\u00a0MM Faria. 2023. Lossy image compression in a preclinical multimodal imaging study. Journal of Digital Imaging 36 4 (2023) 1826\u20131850.","DOI":"10.1007\/s10278-023-00800-5"},{"key":"e_1_3_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i18.29957"},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2006.100"},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_3_1_17_2","unstructured":"Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1503.02531 (2015)."},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"crossref","unstructured":"Ruitao Hou Teng Huang Hongyang Yan Lishan Ke and Weixuan Tang. 2023. A stealthy and robust backdoor attack via frequency domain transform. World Wide Web 26 5 (2023) 2767\u20132783.","DOI":"10.1007\/s11280-023-01153-3"},{"key":"e_1_3_3_1_19_2","doi-asserted-by":"crossref","unstructured":"Quan Huynh-Thu and Mohammed Ghanbari. 2008. Scope of validity of PSNR in image\/video quality assessment. Electronics letters 44 13 (2008) 800\u2013801.","DOI":"10.1049\/el:20080522"},{"key":"e_1_3_3_1_20_2","first-page":"1937","volume-title":"30th USENIX security symposium (USENIX Security 21)","author":"Jia Hengrui","year":"2021","unstructured":"Hengrui Jia, Christopher\u00a0A Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot. 2021. Entangled watermarks as a defense against model extraction. In 30th USENIX security symposium (USENIX Security 21). 1937\u20131954."},{"key":"e_1_3_3_1_21_2","first-page":"16696","volume-title":"International Conference on Machine Learning","author":"Kim Byungjoo","year":"2023","unstructured":"Byungjoo Kim, Suyoung Lee, Seanie Lee, Sooel Son, and Sung\u00a0Ju Hwang. 2023. Margin-based neural network watermarking. In International Conference on Machine Learning. PMLR, 16696\u201316711."},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00570"},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"crossref","unstructured":"Jesse\u00a0D Kornblum. 2008. Using JPEG quantization tables to identify imagery processed by software. digital investigation 5 (2008) S21\u2013S25.","DOI":"10.1016\/j.diin.2008.05.004"},{"key":"e_1_3_3_1_24_2","unstructured":"Alex Krizhevsky Geoffrey Hinton et\u00a0al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"crossref","unstructured":"Lamyanba Laishram Muhammad Shaheryar Jong\u00a0Taek Lee and Soon\u00a0Ki Jung. 2025. Toward a privacy-preserving face recognition system: A survey of leakages and solutions. Comput. Surveys 57 6 (2025) 1\u201338.","DOI":"10.1145\/3673224"},{"key":"e_1_3_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i12.26750"},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359801"},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_32"},{"key":"e_1_3_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833693"},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"crossref","unstructured":"Peizhuo Lv Pan Li Shengzhi Zhang Kai Chen Ruigang Liang Hualong Ma Yue Zhao and Yingjiu Li. 2023. A robustness-assured white-box watermark in neural networks. IEEE Transactions on Dependable and Secure Computing 20 6 (2023) 5214\u20135229.","DOI":"10.1109\/TDSC.2023.3242737"},{"key":"e_1_3_3_1_31_2","unstructured":"Peizhuo Lv Pan Li Shenchen Zhu Shengzhi Zhang Kai Chen Ruigang Liang Chang Yue Fan Xiang Yuling Cai Hualong Ma et\u00a0al. 2022. Ssl-wm: A black-box watermarking approach for encoders pre-trained by self-supervised learning. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2209.03563 (2022)."},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00099"},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329808"},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"crossref","unstructured":"Hewang Nie and Songfeng Lu. 2024. Fedcrmw: Federated model ownership verification with compression-resistant model watermarking. Expert Systems with Applications 249 (2024) 123776.","DOI":"10.1016\/j.eswa.2024.123776"},{"key":"e_1_3_3_1_35_2","doi-asserted-by":"crossref","unstructured":"Hewang Nie Songfeng Lu Junjun Wu and Jianxin Zhu. 2024. Deep model intellectual property protection with compression-resistant model watermarking. IEEE Transactions on Artificial Intelligence 5 7 (2024) 3362\u20133373.","DOI":"10.1109\/TAI.2024.3351116"},{"key":"e_1_3_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"crossref","unstructured":"Kaiyi Pang Tao Qi Chuhan Wu Minhao Bai Minghu Jiang and Yongfeng Huang. 2025. ModelShield: Adaptive and Robust Watermark against Model Extraction Attack. IEEE Transactions on Information Forensics and Security (2025).","DOI":"10.1109\/TIFS.2025.3530691"},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.41"},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"crossref","unstructured":"Wojciech Samek Gr\u00e9goire Montavon Sebastian Lapuschkin Christopher\u00a0J Anders and Klaus-Robert M\u00fcller. 2021. Explaining deep neural networks and beyond: A review of methods and applications. Proc. IEEE 109 3 (2021) 247\u2013278.","DOI":"10.1109\/JPROC.2021.3060483"},{"key":"e_1_3_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1142\/4610"},{"key":"e_1_3_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612515"},{"key":"e_1_3_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3615211"},{"key":"e_1_3_3_1_45_2","unstructured":"Laurens Van\u00a0der Maaten and Geoffrey Hinton. 2008. Visualizing data using t-SNE. JMLR (2008)."},{"key":"e_1_3_3_1_46_2","doi-asserted-by":"crossref","unstructured":"Gregory\u00a0K Wallace. 1991. The JPEG still picture compression standard. Commun. ACM 34 4 (1991) 30\u201344.","DOI":"10.1145\/103085.103089"},{"key":"e_1_3_3_1_47_2","doi-asserted-by":"crossref","unstructured":"Wenbo Wan Jun Wang Yunming Zhang Jing Li Hui Yu and Jiande Sun. 2022. A comprehensive survey on robust image watermarking. Neurocomputing 488 (2022) 226\u2013247.","DOI":"10.1016\/j.neucom.2022.02.083"},{"key":"e_1_3_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450000"},{"key":"e_1_3_3_1_49_2","doi-asserted-by":"crossref","unstructured":"Zhou Wang Alan\u00a0C Bovik Hamid\u00a0R Sheikh and Eero\u00a0P Simoncelli. 2004. Image quality assessment: from error visibility to structural similarity. IEEE transactions on image processing 13 4 (2004) 600\u2013612.","DOI":"10.1109\/TIP.2003.819861"},{"key":"e_1_3_3_1_50_2","doi-asserted-by":"crossref","unstructured":"Shaowu Wu Wei Lu Xiaolin Yin and Rui Yang. 2025. Robust watermarking against arbitrary scaling and cropping attacks. Signal Processing 226 (2025) 109655.","DOI":"10.1016\/j.sigpro.2024.109655"},{"key":"e_1_3_3_1_51_2","unstructured":"Zuping Xi Zuomin Qu Wei Lu Xiangyang Luo and Xiaochun Cao. 2024. Invisible DNN Watermarking Against Model Extraction Attack. IEEE Transactions on Cybernetics (2024)."},{"key":"e_1_3_3_1_52_2","first-page":"2347","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Yan Yifan","year":"2023","unstructured":"Yifan Yan, Xudong Pan, Mi Zhang, and Min Yang. 2023. Rethinking { White-Box} watermarks on deep learning models under neural structural obfuscation. In 32nd USENIX Security Symposium (USENIX Security 23). 2347\u20132364."},{"key":"e_1_3_3_1_53_2","unstructured":"Sze\u00a0Jue Yang Quang Nguyen Chee\u00a0Seng Chan and Khoa\u00a0D Doan. 2023. Everyone Can Attack: Repurpose Lossy Compression as a Natural Backdoor Attack. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2308.16684 (2023)."},{"key":"e_1_3_3_1_54_2","unstructured":"Yunfei Yang. 2026. Source Code. https:\/\/github.com\/yangyunfei16\/ComMark."},{"key":"e_1_3_3_1_55_2","unstructured":"Yunfei Yang Xiaojun Chen Zhendong Zhao Yu Zhou Xiaoyan Gu and Juan Cao. 2025. ComMark: Covert and Robust Black-Box Model Watermarking with Compressed Samples. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2512.15641 (2025)."},{"key":"e_1_3_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.3233\/FAIA230610"},{"key":"e_1_3_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6976"},{"key":"e_1_3_3_1_58_2","unstructured":"Jie Zhang Dongdong Chen Jing Liao Weiming Zhang Huamin Feng Gang Hua and Nenghai Yu. 2021. Deep model intellectual property protection via deep watermarking. IEEE Transactions on Pattern Analysis and Machine Intelligence 44 8 (2021) 4005\u20134020."},{"key":"e_1_3_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"e_1_3_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"e_1_3_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00446"},{"key":"e_1_3_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3681610"}],"event":{"name":"ICMR '26: International Conference on Multimedia Retrieval","location":"Amsterdam The Netherlands","acronym":"ICMR '26","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 2026 International Conference on Multimedia Retrieval"],"original-title":[],"deposited":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T15:39:48Z","timestamp":1781537988000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3805622.3810742"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,15]]},"references-count":61,"alternative-id":["10.1145\/3805622.3810742","10.1145\/3805622"],"URL":"https:\/\/doi.org\/10.1145\/3805622.3810742","relation":{},"subject":[],"published":{"date-parts":[[2026,6,15]]},"assertion":[{"value":"2026-06-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}