{"id":"https://openalex.org/W4288057808","doi":"https://doi.org/10.1109/sp46214.2022.9833693","title":"SoK: How Robust is Image Classification Deep Neural Network Watermarking?","display_name":"SoK: How Robust is Image Classification Deep Neural Network Watermarking?","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4288057808","doi":"https://doi.org/10.1109/sp46214.2022.9833693"},"language":"en","primary_location":{"id":"doi:10.1109/sp46214.2022.9833693","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833693","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5086633938","display_name":"Nils Lukas","orcid":"https://orcid.org/0009-0001-5891-9154"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Nils Lukas","raw_affiliation_strings":["University of Waterloo,Waterloo,Canada","University of Waterloo, Waterloo, Canada"],"affiliations":[{"raw_affiliation_string":"University of Waterloo,Waterloo,Canada","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084659611","display_name":"Edward Jiang","orcid":null},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Edward Jiang","raw_affiliation_strings":["University of Waterloo,Waterloo,Canada","University of Waterloo, Waterloo, Canada"],"affiliations":[{"raw_affiliation_string":"University of Waterloo,Waterloo,Canada","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101905224","display_name":"Xinda Li","orcid":"https://orcid.org/0009-0009-0077-2469"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Xinda Li","raw_affiliation_strings":["University of Waterloo,Waterloo,Canada","University of Waterloo, Waterloo, Canada"],"affiliations":[{"raw_affiliation_string":"University of Waterloo,Waterloo,Canada","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102985450","display_name":"Florian Kerschbaum","orcid":"https://orcid.org/0000-0003-4288-2286"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Florian Kerschbaum","raw_affiliation_strings":["University of Waterloo,Waterloo,Canada","University of Waterloo, Waterloo, Canada"],"affiliations":[{"raw_affiliation_string":"University of Waterloo,Waterloo,Canada","institution_ids":["https://openalex.org/I151746483"]},{"raw_affiliation_string":"University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5086633938"],"corresponding_institution_ids":["https://openalex.org/I151746483"],"apc_list":null,"apc_paid":null,"fwci":6.4048,"has_fulltext":false,"cited_by_count":63,"citation_normalized_percentile":{"value":0.9745071,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"787","last_page":"804"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11636","display_name":"Artificial Intelligence in Healthcare and Education","score":0.9419000148773193,"subfield":{"id":"https://openalex.org/subfields/2718","display_name":"Health Informatics"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9294000267982483,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.9621756076812744},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.9042452573776245},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.7422192096710205},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7362578511238098},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5254201889038086},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5227123498916626},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5114878416061401},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4260559678077698},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.42367714643478394},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3909358084201813},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.36513805389404297},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3482612371444702}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.9621756076812744},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.9042452573776245},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.7422192096710205},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7362578511238098},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5254201889038086},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5227123498916626},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5114878416061401},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4260559678077698},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.42367714643478394},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3909358084201813},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.36513805389404297},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3482612371444702},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/sp46214.2022.9833693","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833693","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6299999952316284,"display_name":"Clean water and sanitation","id":"https://metadata.un.org/sdg/6"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":85,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1821462560","https://openalex.org/W1945616565","https://openalex.org/W2108598243","https://openalex.org/W2117037448","https://openalex.org/W2163605009","https://openalex.org/W2183341477","https://openalex.org/W2194321275","https://openalex.org/W2194775991","https://openalex.org/W2279098554","https://openalex.org/W2325939864","https://openalex.org/W2461943168","https://openalex.org/W2524428287","https://openalex.org/W2572504188","https://openalex.org/W2579318729","https://openalex.org/W2607219512","https://openalex.org/W2612637113","https://openalex.org/W2726204845","https://openalex.org/W2764043458","https://openalex.org/W2768064608","https://openalex.org/W2796299376","https://openalex.org/W2796558322","https://openalex.org/W2806082141","https://openalex.org/W2807363941","https://openalex.org/W2896457183","https://openalex.org/W2909703150","https://openalex.org/W2916845318","https://openalex.org/W2934843808","https://openalex.org/W2937447982","https://openalex.org/W2942091739","https://openalex.org/W2947527202","https://openalex.org/W2962898354","https://openalex.org/W2963163009","https://openalex.org/W2963303354","https://openalex.org/W2963446712","https://openalex.org/W2963466847","https://openalex.org/W2963626858","https://openalex.org/W2964014389","https://openalex.org/W2964137095","https://openalex.org/W2981828710","https://openalex.org/W2991067531","https://openalex.org/W3006874538","https://openalex.org/W3081488247","https://openalex.org/W3097217077","https://openalex.org/W3102720581","https://openalex.org/W3102733833","https://openalex.org/W3156793535","https://openalex.org/W3158240034","https://openalex.org/W3166396011","https://openalex.org/W3168455774","https://openalex.org/W4246193833","https://openalex.org/W4255421341","https://openalex.org/W4288057808","https://openalex.org/W4288083516","https://openalex.org/W4288322434","https://openalex.org/W4293846201","https://openalex.org/W4295312788","https://openalex.org/W4300725094","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6638523607","https://openalex.org/W6640425456","https://openalex.org/W6684191040","https://openalex.org/W6695314431","https://openalex.org/W6725195833","https://openalex.org/W6727208969","https://openalex.org/W6739868092","https://openalex.org/W6745148473","https://openalex.org/W6747838042","https://openalex.org/W6750186640","https://openalex.org/W6750655628","https://openalex.org/W6755207826","https://openalex.org/W6758359881","https://openalex.org/W6758508162","https://openalex.org/W6763527923","https://openalex.org/W6764249721","https://openalex.org/W6766978945","https://openalex.org/W6770411749","https://openalex.org/W6770920902","https://openalex.org/W6773816653","https://openalex.org/W6774150056","https://openalex.org/W6775078712","https://openalex.org/W6775298725","https://openalex.org/W6791353385"],"related_works":["https://openalex.org/W2137394636","https://openalex.org/W2358993821","https://openalex.org/W1516446231","https://openalex.org/W1559740347","https://openalex.org/W2098152888","https://openalex.org/W2040356834","https://openalex.org/W2381486749","https://openalex.org/W2361184779","https://openalex.org/W2385289568","https://openalex.org/W2367449261"],"abstract_inverted_index":{"Deep":[0],"Neural":[1],"Network":[2],"(DNN)":[3],"watermarking":[4,32,76,95,151,161,181,200,292],"is":[5,43,56,202,238,262],"a":[6,24,49,65,75,103,244,299,307,316],"method":[7],"for":[8,160,177,218],"provenance":[9,29],"verification":[10],"of":[11,53,61,69,106,175,197,246,249,259,268,303,319],"DNN":[12,150],"models.":[13],"Watermarking":[14],"should":[15],"be":[16,279,296],"robust":[17,101,203,263],"against":[18,48,64,102,264,298],"watermark":[19],"removal":[20,70,107,119,131,136,145,164,228,304],"attacks":[21,146,214,270,277,284,305],"that":[22,27,34,97,115,195,208,222,276,285,291],"derive":[23,122],"surrogate":[25,123,220],"model":[26],"evades":[28],"verification.":[30],"Many":[31],"schemes":[33,96,152,162,201,209,261,293],"claim":[35,98],"robustness":[36,42,78,99,237],"have":[37,126,223],"been":[38,128,225],"proposed,":[39],"but":[40,125],"their":[41,83,254],"only":[44],"validated":[45],"in":[46,85,154,204,235],"isolation":[47],"relatively":[50],"small":[51],"set":[52,68,105,302],"attacks.":[54,71,108,137,165,229],"There":[55],"no":[57],"systematic,":[58],"empirical":[59,167],"evaluation":[60,168,242,320],"these":[62],"claims":[63],"common,":[66],"comprehensive":[67],"This":[72,230],"uncertainty":[73],"about":[74],"scheme\u2019s":[77],"causes":[79],"difficulty":[80],"to":[81,148,211,232,252,295,327],"trust":[82],"deployment":[84],"practice.":[86,205],"In":[87],"this":[88,155],"paper,":[89],"we":[90],"evaluate":[91],"whether":[92],"recently":[93],"proposed":[94],"are":[100,117,143,322],"large":[104],"We":[109,157,206,274,289],"survey":[110],"methods":[111,217],"from":[112],"the":[113,149,184,198,247,260,269],"literature":[114],"(i)":[116],"known":[118,216],"attacks,":[120,132,266],"(ii)":[121],"models":[124,221],"not":[127,224],"evaluated":[129,226,297],"as":[130,227],"and":[133,140,163,180,189,215,281,315],"(iii)":[134],"novel":[135,144],"Weight":[138],"shifting":[139],"smooth":[141],"retraining":[142],"adapted":[147],"surveyed":[153,199],"paper.":[156],"propose":[158],"taxonomies":[159],"Our":[166,241,312],"includes":[169,243],"an":[170],"ablation":[171],"study":[172,193],"over":[173],"sets":[174],"parameters":[176],"each":[178,250],"attack":[179,251],"scheme":[182],"on":[183],"image":[185],"classification":[186],"datasets":[187],"CIFAR-10":[188],"ImageNet.":[190],"Surprisingly,":[191],"our":[192,330],"shows":[194],"none":[196,258,267],"find":[207,282],"fail":[210],"withstand":[212],"adaptive":[213],"deriving":[219],"points":[231],"intrinsic":[233],"flaws":[234],"how":[236],"currently":[239],"evaluated.":[240],"discussion":[245],"runtime":[248],"underpin":[253],"practical":[255],"relevance.":[256],"While":[257],"all":[265,272,287],"removes":[271],"watermarks.":[273,288],"show":[275,290],"can":[278],"combined":[280,283],"remove":[286],"need":[294],"more":[300,308],"extensive":[301],"with":[306],"realistic":[309],"adversary":[310],"model.":[311],"source":[313],"code":[314],"complete":[317],"dataset":[318],"results":[321],"publicly":[323],"available,":[324],"which":[325],"allows":[326],"independently":[328],"verify":[329],"conclusions.":[331]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":20},{"year":2024,"cited_by_count":17},{"year":2023,"cited_by_count":19},{"year":2022,"cited_by_count":5}],"updated_date":"2026-03-09T08:58:05.943551","created_date":"2025-10-10T00:00:00"}
