{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T11:50:38Z","timestamp":1764157838899,"version":"3.46.0"},"reference-count":29,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T00:00:00Z","timestamp":1764115200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006407","name":"Natural Science Foundation of Henan Province","doi-asserted-by":"publisher","award":["252300420376"],"award-info":[{"award-number":["252300420376"]}],"id":[{"id":"10.13039\/501100006407","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017700","name":"Henan Provincial Science and Technology Research Project","doi-asserted-by":"publisher","award":["252102210163"],"award-info":[{"award-number":["252102210163"]}],"id":[{"id":"10.13039\/501100017700","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Program of the Higher Education Institutions of Henan Province","award":["26A520015","26A520014"],"award-info":[{"award-number":["26A520015","26A520014"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Traditional image watermarking technology focuses on the robustness and imperceptibility of the copyright information embedded in the cover image. However, in addition to copyright theft, the cover images stored and transmitted in the open network environment is facing the threat of being identified and retrieved by deep neural network (DNN) with malicious purpose, which is a new privacy threat. Therefore, it is essential to protect the copyright and the privacy of cover image simultaneously. In this paper, a novel cover-concealed image watermarking (CCIW) is proposed, which combines conditional generative adversarial networks with channel attention mechanisms to generate adversarial examples of the cover image containing invisible copyright information. This method can effectively prevent privacy leakage and copyright infringement simultaneously, since the cover image cannot be collected and processed by DNNs without permission, and the embedded copyright information is hardly to be removed. The experimental results show that the proposed method achieved a success rate of adversarial attack over 98% on the Caltech256 dataset, and the generated adversarial examples have good image quality. The accuracy of copyright information extraction is close to 100%, and it also exhibits good robustness in different noise environments.<\/jats:p>","DOI":"10.3390\/e27121198","type":"journal-article","created":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T11:43:22Z","timestamp":1764157402000},"page":"1198","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["CCIW: Cover-Concealed Image Watermarking for Dual Protection of Privacy and Copyright"],"prefix":"10.3390","volume":"27","author":[{"given":"Ruiping","family":"Li","sequence":"first","affiliation":[{"name":"Information Construction and Management Office, Henan Normal University, Xinxiang 453007, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Si","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer and Information Engineering, Henan Normal University, Xinxiang 453007, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ming","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer and Information Engineering, Henan Normal University, Xinxiang 453007, China"},{"name":"Henan Key Laboratory of Educational Artificial Intelligence and Personalized Learning, Xinxiang 453007, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hua","family":"Ren","sequence":"additional","affiliation":[{"name":"School of Computer and Information Engineering, Henan Normal University, Xinxiang 453007, China"},{"name":"Henan Key Laboratory of Educational Artificial Intelligence and Personalized Learning, Xinxiang 453007, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,26]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1038\/nature14539","article-title":"Deep learning","volume":"521","author":"Lecun","year":"2015","journal-title":"Nature"},{"key":"ref_2","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_3","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2014). Explaining and Harnessing Adversarial Examples. arXiv."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201326). Towards evaluating the robustness of neural networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Xiao, C., Li, B., Zhu, J.Y., He, W., Liu, M., and Song, D. (2018). Generating adversarial examples with adversarial networks. arXiv.","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref_6","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One pixel attack for fooling deep neural networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Zhu, T., Yin, Z., Lyu, W., Zhang, J., and Luo, B. (2023, January 18\u201323). Imperceptible Adversarial Attack on S Channel of HSV Colorspace. Proceedings of the 2023 International Joint Conference on Neural Networks (IJCNN), Gold Coast, Australia.","DOI":"10.1109\/IJCNN54540.2023.10191049"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.patrec.2022.12.018","article-title":"Reversible attack based on adversarial perturbation and reversible data hiding in YUV colorspace","volume":"166","author":"Yin","year":"2023","journal-title":"Pattern Recognit. Lett."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"105094","DOI":"10.1016\/j.imavis.2024.105094","article-title":"Black-box reversible adversarial examples with invertible neural network","volume":"147","author":"Huang","year":"2024","journal-title":"Image Vis. Comput."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"43367","DOI":"10.1007\/s11042-023-15177-4","article-title":"A robust semi-fragile watermarking system using Pseudo-Zernike moments and dual tree complex wavelet transform for social media content authentication","volume":"82","author":"Agilandeeswari","year":"2023","journal-title":"Multimed. Tools Appl."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"7310","DOI":"10.1109\/TCSVT.2023.3279116","article-title":"Robust reversible watermarking by fractional order Zernike moments and pseudo-zernike moments","volume":"33","author":"Fu","year":"2023","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1593","DOI":"10.1109\/TCSVT.2022.3216849","article-title":"A highly robust reversible watermarking scheme using embedding optimization and rounded error compensation","volume":"33","author":"Tang","year":"2022","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Zhu, J., Kaplan, R., Johnson, J., and Li, F.-F. (2018). HiDDeN: Hiding data with deep networks. arXiv.","DOI":"10.1007\/978-3-030-01267-0_40"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Liu, Y., Guo, M., Zhang, J., Zhu, Y., and Xie, X. (2019, January 21\u201325). A novel two-stage separable deep learning framework for practical blind watermarking. Proceedings of the 27th ACM International Conference on Multimedia, Nice, France.","DOI":"10.1145\/3343031.3351025"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Jia, Z., Fang, H., and Zhang, W. (2021, January 20\u201324). MBRS: Enhancing Robustness of DNN-based Watermarking by Mini-Batch of Real and Simulated JPEG Compression. Proceedings of the 29th ACM International Conference on Multimedia, Virtual Event.","DOI":"10.1145\/3474085.3475324"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Padhi, S.K., Tiwari, A., and Ali, S.S. (2025). Deep Learning-based Dual Watermarking for Image Copyright Protection and Authentication. arXiv.","DOI":"10.1109\/TAI.2024.3485519"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Jia, X., Wei, X., Cao, X., and Han, X. (2020, January 12\u201316). Adv-watermark: A Novel Watermark Perturbation for Adversarial Examples. Proceedings of the 28th ACM International Conference on Multimedia, Seattle, WA, USA.","DOI":"10.1145\/3394171.3413976"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"301","DOI":"10.1109\/TC.2021.3065172","article-title":"FAWA: Fast Adversarial Watermark Attack","volume":"73","author":"Jiang","year":"2021","journal-title":"IEEE Trans. Comput."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Wang, D., Li, M., and Zhang, Y. (2022). Adversarial data hiding in digital images. Entropy, 24.","DOI":"10.3390\/e24060749"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"103222","DOI":"10.1016\/j.ipm.2022.103222","article-title":"Adversarial data hiding with only one pixel","volume":"60","author":"Li","year":"2023","journal-title":"Inf. Process. Manag."},{"key":"ref_22","first-page":"43","article-title":"Invisible Adversarial Watermarking: A Novel Security Mechanism for Enhancing Copyright Protection","volume":"21","author":"Wang","year":"2024","journal-title":"ACM Trans. Multimed. Comput. Commun. Appl."},{"key":"ref_23","unstructured":"Mirza, M., and Osindero, S. (2014). Conditional Generative Adversarial Nets. arXiv."},{"key":"ref_24","unstructured":"Ba, J., Mnih, V., and Kavukcuoglu, K. (2014). Multiple object recognition with visual attention. arXiv."},{"key":"ref_25","first-page":"732","article-title":"Deep knowledge tracking optimization model based on self-attention mechanism and bidirectional GRU neural network","volume":"39","author":"Li","year":"2022","journal-title":"Appl. Res. Comput."},{"key":"ref_26","first-page":"2048","article-title":"Show, Attend and Tell: Neural Image Caption Generation with Visual Attention","volume":"37","author":"Xu","year":"2015","journal-title":"Comput. Sci."},{"key":"ref_27","unstructured":"Yu, C. (2020, January 7\u201312). Attention Based Data Hiding with Generative Adversarial Networks. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"888","DOI":"10.1109\/TNSE.2021.3139671","article-title":"Channel Attention Image Steganography with Generative Adversarial Networks","volume":"9","author":"Tan","year":"2021","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"677","DOI":"10.1109\/CISP.2008.179","article-title":"Integral image based fast algorithm for two-dimensional Otsu thresholding","volume":"Volume 3","author":"Lang","year":"2008","journal-title":"Proceedings of the 2008 Congress on Image and Signal Processing"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/12\/1198\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T11:49:09Z","timestamp":1764157749000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/12\/1198"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,26]]},"references-count":29,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["e27121198"],"URL":"https:\/\/doi.org\/10.3390\/e27121198","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,26]]}}}