{"id":"https://openalex.org/W4393404818","doi":"https://doi.org/10.1109/tdsc.2024.3384416","title":"Robust and Imperceptible Black-Box DNN Watermarking Based on Fourier Perturbation Analysis and Frequency Sensitivity Clustering","display_name":"Robust and Imperceptible Black-Box DNN Watermarking Based on Fourier Perturbation Analysis and Frequency Sensitivity Clustering","publication_year":2024,"publication_date":"2024-04-02","ids":{"openalex":"https://openalex.org/W4393404818","doi":"https://doi.org/10.1109/tdsc.2024.3384416"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2024.3384416","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2024.3384416","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Yong Liu","orcid":"https://orcid.org/0000-0001-8478-8525"},"institutions":[{"id":"https://openalex.org/I113940042","display_name":"Shanghai University","ror":"https://ror.org/006teas31","country_code":"CN","type":"education","lineage":["https://openalex.org/I113940042"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yong Liu","raw_affiliation_strings":["School of Communication and Information Engineering, Shanghai University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Communication and Information Engineering, Shanghai University, Shanghai, China","institution_ids":["https://openalex.org/I113940042"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049733139","display_name":"Hanzhou Wu","orcid":"https://orcid.org/0000-0002-1599-7232"},"institutions":[{"id":"https://openalex.org/I113940042","display_name":"Shanghai University","ror":"https://ror.org/006teas31","country_code":"CN","type":"education","lineage":["https://openalex.org/I113940042"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hanzhou Wu","raw_affiliation_strings":["School of Communication and Information Engineering, Shanghai University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Communication and Information Engineering, Shanghai University, Shanghai, China","institution_ids":["https://openalex.org/I113940042"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5071724015","display_name":"Xinpeng Zhang","orcid":"https://orcid.org/0000-0001-5867-1315"},"institutions":[{"id":"https://openalex.org/I113940042","display_name":"Shanghai University","ror":"https://ror.org/006teas31","country_code":"CN","type":"education","lineage":["https://openalex.org/I113940042"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinpeng Zhang","raw_affiliation_strings":["School of Communication and Information Engineering, Shanghai University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Communication and Information Engineering, Shanghai University, Shanghai, China","institution_ids":["https://openalex.org/I113940042"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I113940042"],"apc_list":null,"apc_paid":null,"fwci":2.2049,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.88478959,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":99},"biblio":{"volume":"21","issue":"6","first_page":"5766","last_page":"5780"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9962999820709229,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9933000206947327,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6873140335083008},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.6686681509017944},{"id":"https://openalex.org/keywords/sensitivity","display_name":"Sensitivity (control systems)","score":0.5735902190208435},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.5732172131538391},{"id":"https://openalex.org/keywords/fourier-transform","display_name":"Fourier transform","score":0.5152197480201721},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5113641619682312},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.48310303688049316},{"id":"https://openalex.org/keywords/perturbation","display_name":"Perturbation (astronomy)","score":0.45075365900993347},{"id":"https://openalex.org/keywords/speech-recognition","display_name":"Speech recognition","score":0.35970014333724976},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.33816975355148315},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.32478058338165283},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.21005091071128845},{"id":"https://openalex.org/keywords/physics","display_name":"Physics","score":0.15747806429862976},{"id":"https://openalex.org/keywords/electronic-engineering","display_name":"Electronic engineering","score":0.14992034435272217},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.10384717583656311},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.09975939989089966}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6873140335083008},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.6686681509017944},{"id":"https://openalex.org/C21200559","wikidata":"https://www.wikidata.org/wiki/Q7451068","display_name":"Sensitivity (control systems)","level":2,"score":0.5735902190208435},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.5732172131538391},{"id":"https://openalex.org/C102519508","wikidata":"https://www.wikidata.org/wiki/Q6520159","display_name":"Fourier transform","level":2,"score":0.5152197480201721},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5113641619682312},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.48310303688049316},{"id":"https://openalex.org/C177918212","wikidata":"https://www.wikidata.org/wiki/Q803623","display_name":"Perturbation (astronomy)","level":2,"score":0.45075365900993347},{"id":"https://openalex.org/C28490314","wikidata":"https://www.wikidata.org/wiki/Q189436","display_name":"Speech recognition","level":1,"score":0.35970014333724976},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.33816975355148315},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.32478058338165283},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.21005091071128845},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.15747806429862976},{"id":"https://openalex.org/C24326235","wikidata":"https://www.wikidata.org/wiki/Q126095","display_name":"Electronic engineering","level":1,"score":0.14992034435272217},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.10384717583656311},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.09975939989089966},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tdsc.2024.3384416","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2024.3384416","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Climate action","id":"https://metadata.un.org/sdg/13","score":0.5299999713897705}],"awards":[{"id":"https://openalex.org/G2211833943","display_name":null,"funder_award_id":"61902235","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7263650625","display_name":null,"funder_award_id":"U23B2023","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":45,"referenced_works":["https://openalex.org/W1993137812","https://openalex.org/W2002427601","https://openalex.org/W2052987786","https://openalex.org/W2133665775","https://openalex.org/W2161160262","https://openalex.org/W2194775991","https://openalex.org/W2579318729","https://openalex.org/W2740924709","https://openalex.org/W2806082141","https://openalex.org/W2890304135","https://openalex.org/W2914483840","https://openalex.org/W2952608669","https://openalex.org/W2963446712","https://openalex.org/W2964137095","https://openalex.org/W2994720379","https://openalex.org/W2997717738","https://openalex.org/W3022293880","https://openalex.org/W3023104975","https://openalex.org/W3053555102","https://openalex.org/W3087931608","https://openalex.org/W3092793669","https://openalex.org/W3132481243","https://openalex.org/W3135872251","https://openalex.org/W3156011647","https://openalex.org/W3159280306","https://openalex.org/W3185271965","https://openalex.org/W3185788529","https://openalex.org/W3186017582","https://openalex.org/W3205572447","https://openalex.org/W4220734716","https://openalex.org/W4220734809","https://openalex.org/W4226014375","https://openalex.org/W4320005719","https://openalex.org/W4323345707","https://openalex.org/W4362714395","https://openalex.org/W4382317564","https://openalex.org/W4385382984","https://openalex.org/W4390481384","https://openalex.org/W6637373629","https://openalex.org/W6747838042","https://openalex.org/W6763810570","https://openalex.org/W6766821575","https://openalex.org/W6787972765","https://openalex.org/W6845886309","https://openalex.org/W6854872738"],"related_works":["https://openalex.org/W2361629745","https://openalex.org/W2107922825","https://openalex.org/W3094285444","https://openalex.org/W1568204688","https://openalex.org/W2381262728","https://openalex.org/W2111592878","https://openalex.org/W1846726187","https://openalex.org/W2009856579","https://openalex.org/W1593964766","https://openalex.org/W2387614453"],"abstract_inverted_index":{"Recently,":[0],"more":[1,3,54],"and":[2,97,100,107,131],"attention":[4],"has":[5,102,112],"been":[6],"focused":[7],"on":[8,127,149,195],"the":[9,42,46,50,67,73,82,86,104,108,114,138,146,150,154,166,177,184,190,193],"intellectual":[10],"property":[11],"protection":[12],"of":[13,49,141,145,153,192],"deep":[14],"neural":[15],"networks":[16],"(DNNs),":[17],"promoting":[18],"DNN":[19,33,123,155,194],"watermarking":[20,105,124,173,203],"to":[21,40,64,81,119],"become":[22],"a":[23,78,121],"hot":[24],"research":[25],"topic.":[26],"Compared":[27],"with":[28,206],"embedding":[29],"watermarks":[30,37],"directly":[31],"into":[32],"parameters,":[34],"inserting":[35,77],"trigger-set":[36],"enables":[38],"us":[39],"verify":[41],"ownership":[43],"without":[44],"knowing":[45],"internal":[47],"details":[48],"DNN,":[51],"which":[52,89],"is":[53,61],"suitable":[55],"for":[56,175],"application":[57],"scenarios.":[58],"The":[59],"cost":[60],"we":[62,136,164],"have":[63],"carefully":[65],"craft":[66],"trigger":[68,74,178],"samples.":[69,179],"Mainstream":[70],"methods":[71],"construct":[72],"samples":[75,84],"by":[76,156,161],"noticeable":[79],"pattern":[80],"clean":[83],"in":[85,116,171],"spatial":[87],"domain,":[88],"does":[90],"not":[91,187],"consider":[92],"sample":[93,95,148],"imperceptibility,":[94],"robustness":[96],"model":[98,109],"robustness,":[99],"therefore":[101],"limited":[103],"performance":[106,174,191,204],"generalization.":[110],"It":[111],"motivated":[113],"authors":[115],"this":[117],"paper":[118],"propose":[120],"novel":[122],"method":[125],"based":[126],"Fourier":[128],"perturbation":[129,139],"analysis":[130],"frequency":[132,143,167],"sensitivity":[133],"clustering.":[134],"First,":[135],"analyze":[137],"impact":[140],"different":[142],"components":[144,168],"input":[147],"task":[151],"functionality":[152],"applying":[157],"random":[158],"perturbation.":[159],"Then,":[160],"K-means":[162],"clustering,":[163],"determine":[165],"that":[169,183],"result":[170],"superior":[172],"crafting":[176],"Our":[180],"experiments":[181],"show":[182],"proposed":[185],"work":[186],"only":[188],"maintains":[189],"its":[196],"original":[197],"task,":[198],"but":[199],"also":[200],"provides":[201],"better":[202],"compared":[205],"related":[207],"works.":[208]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":5}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
