{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T11:07:42Z","timestamp":1776337662882,"version":"3.51.2"},"reference-count":35,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2024,11,8]],"date-time":"2024-11-08T00:00:00Z","timestamp":1731024000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["42201444"],"award-info":[{"award-number":["42201444"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["42271431"],"award-info":[{"award-number":["42271431"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["2024JJ8334"],"award-info":[{"award-number":["2024JJ8334"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["22S01"],"award-info":[{"award-number":["22S01"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Hunan Provincial Natural Science Foundation of China","award":["42201444"],"award-info":[{"award-number":["42201444"]}]},{"name":"Hunan Provincial Natural Science Foundation of China","award":["42271431"],"award-info":[{"award-number":["42271431"]}]},{"name":"Hunan Provincial Natural Science Foundation of China","award":["2024JJ8334"],"award-info":[{"award-number":["2024JJ8334"]}]},{"name":"Hunan Provincial Natural Science Foundation of China","award":["22S01"],"award-info":[{"award-number":["22S01"]}]},{"name":"Wuhan University","award":["42201444"],"award-info":[{"award-number":["42201444"]}]},{"name":"Wuhan University","award":["42271431"],"award-info":[{"award-number":["42271431"]}]},{"name":"Wuhan University","award":["2024JJ8334"],"award-info":[{"award-number":["2024JJ8334"]}]},{"name":"Wuhan University","award":["22S01"],"award-info":[{"award-number":["22S01"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>High-quality datasets are essential for training high-performance models, while the process of collection, cleaning, and labeling is costly. As a result, datasets are considered valuable intellectual property. However, when security mechanisms are symmetry-breaking, creating exploitable vulnerabilities, unauthorized use or data leakage can infringe on the copyright of dataset owners. In this study, we design a method to mount clean-label dataset watermarking based on trigger optimization, aiming to protect the copyright of the dataset from infringement. We first perform iterative optimization of the trigger based on a surrogate model, with targets class samples guiding the updates. The process ensures that the optimized triggers contain robust feature representations of the watermark target class. A watermarked dataset is obtained by embedding optimized triggers into randomly selected samples from the watermark target class. If an adversary trains a model with the watermarked dataset, our watermark will manipulate the model\u2019s output. By observing the output of the suspect model on samples with triggers, it can be determined whether the model was trained on the watermarked dataset. The experimental results demonstrate that the proposed method exhibits high imperceptibility and strong robustness against pruning and fine-tuning attacks. Compared to existing methods, the proposed method significantly improves effectiveness at very low watermarking rates.<\/jats:p>","DOI":"10.3390\/sym16111494","type":"journal-article","created":{"date-parts":[[2024,11,8]],"date-time":"2024-11-08T04:02:54Z","timestamp":1731038574000},"page":"1494","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Clean-Label Backdoor Watermarking for Dataset Copyright Protection via Trigger Optimization"],"prefix":"10.3390","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3619-5236","authenticated-orcid":false,"given":"Weitong","family":"Chen","sequence":"first","affiliation":[{"name":"School of Information Engineering, Yangzhou University, Yangzhou 225127, China"},{"name":"Jiangsu Province Engineering Research Center of Knowledge Management and Intelligent Service, Yangzhou 225127, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-6428-7696","authenticated-orcid":false,"given":"Gaoyang","family":"Wei","sequence":"additional","affiliation":[{"name":"School of Information Engineering, Yangzhou University, Yangzhou 225127, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-4042-8674","authenticated-orcid":false,"given":"Xin","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Information Engineering, Yangzhou University, Yangzhou 225127, China"},{"name":"Jiangsu Province Engineering Research Center of Knowledge Management and Intelligent Service, Yangzhou 225127, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3357-249X","authenticated-orcid":false,"given":"Yanyan","family":"Xu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Engineering in Surveying, Mapping and Remote Sensing, Wuhan University, Wuhan 430079, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haibo","family":"Peng","sequence":"additional","affiliation":[{"name":"The Third Surveying and Mapping Institute of Hunan Province, Changsha 410018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yingchen","family":"She","sequence":"additional","affiliation":[{"name":"The Third Surveying and Mapping Institute of Hunan Province, Changsha 410018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2024,11,8]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"144","DOI":"10.1016\/j.jmsy.2018.01.003","article-title":"Deep learning for smart manufacturing: Methods and applications","volume":"48","author":"Wang","year":"2018","journal-title":"J. Manuf. Syst."},{"key":"ref_2","unstructured":"Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., and Gelly, S. (2021, January 3\u20137). An Image is Worth 16 \u00d7 16 Words: Transformers for Image Recognition at Scale. Proceedings of the International Conference on Learning Representations, Virtual."},{"key":"ref_3","unstructured":"Tan, M., and Le, Q. (2019, January 10\u201315). Efficientnet: Rethinking model scaling for convolutional neural networks. Proceedings of the International Conference on Machine Learning, PMLR, Long Beach, CA, USA."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"685","DOI":"10.1007\/s12525-021-00475-2","article-title":"Machine learning and deep learning","volume":"31","author":"Janiesch","year":"2021","journal-title":"Electron. Mark."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"669","DOI":"10.1038\/s42256-022-00516-1","article-title":"Advances, challenges and opportunities in creating data for trustworthy AI","volume":"4","author":"Liang","year":"2022","journal-title":"Nat. Mach. Intell."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1328","DOI":"10.1109\/TKDE.2019.2946162","article-title":"A survey on data collection for machine learning: A big data-ai integration perspective","volume":"33","author":"Roh","year":"2019","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Abdollahi, A., Pradhan, B., Shukla, N., Chakraborty, S., and Alamri, A. (2020). Deep learning approaches applied to remote sensing datasets for road extraction: A state-of-the-art review. Remote Sens., 12.","DOI":"10.3390\/rs12091444"},{"key":"ref_8","unstructured":"Maini, P., Yaghini, M., and Papernot, N. (2021). Dataset inference: Ownership resolution in machine learning. arXiv."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Ali, A., Pinciroli, R., Yan, F., and Smirni, E. (2020, January 9\u201319). Batch: Machine learning inference serving on serverless platforms with adaptive batching. Proceedings of the SC20: International Conference for High Performance Computing, Networking, Storage and Analysis, Virtual.","DOI":"10.1109\/SC41405.2020.00073"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Wu, C.J., Brooks, D., Chen, K., Chen, D., Choudhury, S., Dukhan, M., Hazelwood, K., Isaac, E., Jia, Y., and Jia, B. (2019, January 16\u201320). Machine learning at facebook: Understanding inference at the edge. Proceedings of the 2019 IEEE International Symposium on High Performance Computer Architecture (HPCA), Washington, DC, USA.","DOI":"10.1109\/HPCA.2019.00048"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"104035","DOI":"10.1016\/j.cose.2024.104035","article-title":"Unveiling vulnerabilities in deep learning-based malware detection: Differential privacy driven adversarial attacks","volume":"146","author":"Taheri","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Begum, M., and Uddin, M.S. (2020). Digital image watermarking techniques: A review. Information, 11.","DOI":"10.3390\/info11020110"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"3168","DOI":"10.1109\/TIFS.2020.2985532","article-title":"Identity-based encryption transformation for flexible sharing of encrypted data in public cloud","volume":"15","author":"Deng","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"2318","DOI":"10.1109\/TIFS.2023.3265535","article-title":"Black-box dataset ownership verification via backdoor watermarking","volume":"18","author":"Li","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_15","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., and Song, D. (2017). Targeted backdoor attacks on deep learning systems using data poisoning. arXiv."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","article-title":"Badnets: Evaluating backdooring attacks on deep neural networks","volume":"7","author":"Gu","year":"2019","journal-title":"IEEE Access"},{"key":"ref_17","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., and Shmatikov, V. (2020, January 26\u201328). How to backdoor federated learning. Proceedings of the International Conference on Artificial Intelligence and Statistics, Virtual."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, X., Bailey, J., and Lu, F. (2020, January 23\u201328). Reflection backdoor: A natural backdoor attack on deep neural networks. Proceedings of the Computer Vision\u2014ECCV 2020: 16th European Conference, Glasgow, UK.","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref_19","first-page":"2088","article-title":"Invisible backdoor attacks on deep neural networks via steganography and regularization","volume":"18","author":"Li","year":"2020","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_20","unstructured":"Li, Y., Zhang, Z., Bai, J., Wu, B., Jiang, Y., and Xia, S.T. (2020). Open-sourced dataset protection via backdoor watermarking. arXiv."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Pan, M., Just, H.A., Lyu, L., Qiu, M., and Jia, R. (2023, January 26\u201330). Narcissus: A practical clean-label backdoor attack with limited information. Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Copenhagen, Denmark.","DOI":"10.1145\/3576915.3616617"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1145\/3606274.3606279","article-title":"Did you train on my dataset? towards public dataset protection with cleanlabel backdoor watermarking","volume":"25","author":"Tang","year":"2023","journal-title":"Acm Sigkdd Explor. Newsl."},{"key":"ref_23","unstructured":"Turner, A., Tsipras, D., and Madry, A. (2019). Label-consistent backdoor attacks. arXiv."},{"key":"ref_24","first-page":"19165","article-title":"Sleeper agent: Scalable hidden trigger backdoors for neural networks trained from scratch","volume":"35","author":"Souri","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"14781","DOI":"10.1007\/s00521-020-04831-9","article-title":"On defending against label flipping attacks on malware detection systems","volume":"32","author":"Taheri","year":"2020","journal-title":"Neural Comput. Appl."},{"key":"ref_26","first-page":"13238","article-title":"Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection","volume":"35","author":"Li","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_27","unstructured":"Krizhevsky, A., and Hinton, G. (2009). Learning Multiple Layers of Features from Tiny Images. [Master\u2019s Thesis, University of Toronto]."},{"key":"ref_28","first-page":"3","article-title":"Tiny imagenet visual recognition challenge","volume":"7","author":"Le","year":"2015","journal-title":"CS 231N"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kumar, N., Berg, A.C., Belhumeur, P.N., and Nayar, S.K. (October, January 29). Attribute and simile classifiers for face verification. Proceedings of the 2009 IEEE 12th International Conference on Computer Vision, Kyoto, Japan.","DOI":"10.1109\/ICCV.2009.5459250"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Liu, Z., Luo, P., Wang, X., and Tang, X. (2015, January 7\u201313). Deep learning face attributes in the wild. Proceedings of the IEEE International Conference on Computer Vision, ICCV, Santiago, Chile.","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, CVPR, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Saha, A., Subramanya, A., and Pirsiavash, H. (2020, January 7\u201312). Hidden trigger backdoor attacks. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Zhang, R., Isola, P., Efros, A.A., Shechtman, E., and Wang, O. (2018, January 18\u201323). The unreasonable effectiveness of deep features as a perceptual metric. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref_34","unstructured":"Simonyan, K., and Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv."},{"key":"ref_35","unstructured":"Howard, A., Sandler, M., Chu, G., Chen, L.C., Chen, B., Tan, M., Wang, W., Zhu, Y., Pang, R., and Vasudevan, V. (November, January 27). Searching for mobilenetv3. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Seoul, Republic of Korea."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/16\/11\/1494\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T16:28:36Z","timestamp":1760113716000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/16\/11\/1494"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,8]]},"references-count":35,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2024,11]]}},"alternative-id":["sym16111494"],"URL":"https:\/\/doi.org\/10.3390\/sym16111494","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,8]]}}}