{"id":"https://openalex.org/W4408355651","doi":"https://doi.org/10.1109/icassp49660.2025.10890107","title":"Exploiting Robust Model Watermarking Against the Model Fine-Tuning Attack via Flat Minima Aware Optimizers","display_name":"Exploiting Robust Model Watermarking Against the Model Fine-Tuning Attack via Flat Minima Aware Optimizers","publication_year":2025,"publication_date":"2025-03-12","ids":{"openalex":"https://openalex.org/W4408355651","doi":"https://doi.org/10.1109/icassp49660.2025.10890107"},"language":"en","primary_location":{"id":"doi:10.1109/icassp49660.2025.10890107","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49660.2025.10890107","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2025 - 2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5034780150","display_name":"Dongdong Lin","orcid":"https://orcid.org/0009-0006-4376-3210"},"institutions":[{"id":"https://openalex.org/I180726961","display_name":"Shenzhen University","ror":"https://ror.org/01vy4gh70","country_code":"CN","type":"education","lineage":["https://openalex.org/I180726961"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dongdong Lin","raw_affiliation_strings":["Shenzhen University,Guangdong Provincial Key Laboratory of Intelligent Information Processing,Shenzhen,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Shenzhen University,Guangdong Provincial Key Laboratory of Intelligent Information Processing,Shenzhen,China","institution_ids":["https://openalex.org/I180726961"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038730342","display_name":"Yue Li","orcid":"https://orcid.org/0000-0001-6425-9298"},"institutions":[{"id":"https://openalex.org/I119045251","display_name":"Huaqiao University","ror":"https://ror.org/03frdh605","country_code":"CN","type":"education","lineage":["https://openalex.org/I119045251"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yue Li","raw_affiliation_strings":["Huaqiao University,Xiamen Key Laboratory of Data Security and Blockchain Technology,Xiamen,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Huaqiao University,Xiamen Key Laboratory of Data Security and Blockchain Technology,Xiamen,China","institution_ids":["https://openalex.org/I119045251"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100365163","display_name":"Bin Li","orcid":"https://orcid.org/0000-0002-2613-5451"},"institutions":[{"id":"https://openalex.org/I180726961","display_name":"Shenzhen University","ror":"https://ror.org/01vy4gh70","country_code":"CN","type":"education","lineage":["https://openalex.org/I180726961"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bin Li","raw_affiliation_strings":["Shenzhen University,Guangdong Provincial Key Laboratory of Intelligent Information Processing,Shenzhen,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Shenzhen University,Guangdong Provincial Key Laboratory of Intelligent Information Processing,Shenzhen,China","institution_ids":["https://openalex.org/I180726961"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5047964483","display_name":"Jiwu Huang","orcid":"https://orcid.org/0000-0002-7625-5689"},"institutions":[{"id":"https://openalex.org/I180726961","display_name":"Shenzhen University","ror":"https://ror.org/01vy4gh70","country_code":"CN","type":"education","lineage":["https://openalex.org/I180726961"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiwu Huang","raw_affiliation_strings":["Shenzhen University,Shenzhen Key Laboratory of Media Security,Shenzhen,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Shenzhen University,Shenzhen Key Laboratory of Media Security,Shenzhen,China","institution_ids":["https://openalex.org/I180726961"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.9349,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.72392856,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"5"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12707","display_name":"Vehicle License Plate Recognition","score":0.9948999881744385,"subfield":{"id":"https://openalex.org/subfields/2214","display_name":"Media Technology"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.994700014591217,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/maxima-and-minima","display_name":"Maxima and minima","score":0.8274458646774292},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8258169889450073},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6543502807617188},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5315677523612976},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.36668872833251953},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2664197087287903},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.13922587037086487},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.0930032730102539},{"id":"https://openalex.org/keywords/chemistry","display_name":"Chemistry","score":0.07827621698379517}],"concepts":[{"id":"https://openalex.org/C186633575","wikidata":"https://www.wikidata.org/wiki/Q845060","display_name":"Maxima and minima","level":2,"score":0.8274458646774292},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8258169889450073},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6543502807617188},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5315677523612976},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.36668872833251953},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2664197087287903},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.13922587037086487},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.0930032730102539},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.07827621698379517},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icassp49660.2025.10890107","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49660.2025.10890107","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2025 - 2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W1834627138","https://openalex.org/W2883233582","https://openalex.org/W2952122856","https://openalex.org/W3143336910","https://openalex.org/W4311736699","https://openalex.org/W4312933868","https://openalex.org/W4385573252","https://openalex.org/W4385815557","https://openalex.org/W4386047779","https://openalex.org/W4390872921","https://openalex.org/W4400447110","https://openalex.org/W4401070443","https://openalex.org/W4401568505","https://openalex.org/W4403780894","https://openalex.org/W6631190155","https://openalex.org/W6783600611","https://openalex.org/W6790545018","https://openalex.org/W6802205604","https://openalex.org/W6810200297","https://openalex.org/W6838118415","https://openalex.org/W6849243157","https://openalex.org/W6852705717","https://openalex.org/W6857300250","https://openalex.org/W6862145329","https://openalex.org/W6867763113"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2122982227","https://openalex.org/W2163290991","https://openalex.org/W2361184779","https://openalex.org/W3174961728","https://openalex.org/W2474386553","https://openalex.org/W2125329004","https://openalex.org/W2141752560"],"abstract_inverted_index":{"With":[0],"the":[1,63,81,93,104,109],"rapid":[2],"advancement":[3],"of":[4,59,83,106],"deep":[5],"neural":[6],"networks":[7],"(DNNs),":[8],"model":[9,20,44,84,110,149],"watermarking":[10,85],"has":[11],"emerged":[12],"as":[13],"a":[14,27,71,134],"widely":[15],"adopted":[16],"technique":[17],"for":[18,139],"safeguarding":[19],"copyrights.":[21],"A":[22],"prevalent":[23],"method":[24],"involves":[25],"utilizing":[26],"watermark":[28,32,94,123],"decoder":[29],"to":[30,43,79,121,144],"retrieve":[31],"bits":[33],"from":[34],"generated":[35],"outputs,":[36],"but":[37],"such":[38],"methods":[39],"are":[40],"often":[41],"vulnerable":[42],"fine-tuning":[45,111],"attacks.":[46],"Traditionally,":[47],"this":[48,67,129],"challenge":[49],"is":[50],"mitigated":[51],"through":[52],"adversarial":[53],"training":[54,89],"or":[55],"data":[56],"augmentation,":[57],"both":[58],"which":[60],"significantly":[61,102],"increase":[62],"computational":[64],"burden.":[65],"In":[66],"paper,":[68],"we":[69],"present":[70],"solution":[72],"employing":[73],"Flat":[74],"Minima":[75],"Aware":[76],"(FMA)":[77],"optimizers":[78],"bolster":[80],"robustness":[82,105],"without":[86],"requiring":[87],"additional":[88],"data.":[90],"By":[91],"optimizing":[92],"loss":[95],"with":[96],"flat":[97],"minima":[98],"awareness,":[99],"our":[100,117],"approaches":[101],"enhance":[103],"watermarks":[107],"against":[108],"attack.":[112],"Comprehensive":[113],"experiments":[114],"have":[115],"demonstrated":[116],"method\u2019s":[118],"superior":[119],"ability":[120],"preserve":[122],"integrity.":[124],"These":[125],"findings":[126],"suggest":[127],"that":[128],"innovative":[130],"optimization":[131],"strategy":[132],"offers":[133],"robust":[135],"and":[136,147],"efficient":[137],"pathway":[138],"protecting":[140],"models,":[141],"thereby":[142],"contributing":[143],"more":[145],"secure":[146],"reliable":[148],"copyright":[150],"protection":[151],"mechanisms.":[152]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
