{"id":"https://openalex.org/W4410491796","doi":"https://doi.org/10.1109/tnnls.2025.3565170","title":"Persistence of Backdoor-Based Watermarks for Neural Networks: A Comprehensive Evaluation","display_name":"Persistence of Backdoor-Based Watermarks for Neural Networks: A Comprehensive Evaluation","publication_year":2025,"publication_date":"2025-05-19","ids":{"openalex":"https://openalex.org/W4410491796","doi":"https://doi.org/10.1109/tnnls.2025.3565170","pmid":"https://pubmed.ncbi.nlm.nih.gov/40388282"},"language":"en","primary_location":{"id":"doi:10.1109/tnnls.2025.3565170","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnnls.2025.3565170","pdf_url":null,"source":{"id":"https://openalex.org/S4210175523","display_name":"IEEE Transactions on Neural Networks and Learning Systems","issn_l":"2162-237X","issn":["2162-237X","2162-2388"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Neural Networks and Learning Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5042051596","display_name":"Anh Tu Ngo","orcid":"https://orcid.org/0000-0001-7224-6833"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":true,"raw_author_name":"Anh Tu Ngo","raw_affiliation_strings":["CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"],"affiliations":[{"raw_affiliation_string":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101345596","display_name":"Chuan Song Heng","orcid":null},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Chuan Song Heng","raw_affiliation_strings":["CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"],"affiliations":[{"raw_affiliation_string":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071802339","display_name":"Nandish Chattopadhyay","orcid":"https://orcid.org/0000-0002-1611-9378"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Nandish Chattopadhyay","raw_affiliation_strings":["CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"],"affiliations":[{"raw_affiliation_string":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5089860351","display_name":"Anupam Chattopadhyay","orcid":"https://orcid.org/0000-0002-8818-6983"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Anupam Chattopadhyay","raw_affiliation_strings":["CCDS, Nanyang Technological University Singapore, Jurong West, Singapore"],"affiliations":[{"raw_affiliation_string":"CCDS, Nanyang Technological University Singapore, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5042051596"],"corresponding_institution_ids":["https://openalex.org/I172675005"],"apc_list":null,"apc_paid":null,"fwci":1.319,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.80617406,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":"36","issue":"9","first_page":"15939","last_page":"15950"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.8985000252723694,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.8985000252723694,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10320","display_name":"Neural Networks and Applications","score":0.8740000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12611","display_name":"Neural Networks and Reservoir Computing","score":0.8209999799728394,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9739452600479126},{"id":"https://openalex.org/keywords/persistence","display_name":"Persistence (discontinuity)","score":0.8914809226989746},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5652350187301636},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.44056469202041626},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.43270519375801086},{"id":"https://openalex.org/keywords/econometrics","display_name":"Econometrics","score":0.33110326528549194},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2603757083415985},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.20912376046180725},{"id":"https://openalex.org/keywords/geology","display_name":"Geology","score":0.17506542801856995},{"id":"https://openalex.org/keywords/geotechnical-engineering","display_name":"Geotechnical engineering","score":0.058039337396621704}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9739452600479126},{"id":"https://openalex.org/C2781009140","wikidata":"https://www.wikidata.org/wiki/Q7170389","display_name":"Persistence (discontinuity)","level":2,"score":0.8914809226989746},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5652350187301636},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.44056469202041626},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.43270519375801086},{"id":"https://openalex.org/C149782125","wikidata":"https://www.wikidata.org/wiki/Q160039","display_name":"Econometrics","level":1,"score":0.33110326528549194},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2603757083415985},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.20912376046180725},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.17506542801856995},{"id":"https://openalex.org/C187320778","wikidata":"https://www.wikidata.org/wiki/Q1349130","display_name":"Geotechnical engineering","level":1,"score":0.058039337396621704}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tnnls.2025.3565170","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnnls.2025.3565170","pdf_url":null,"source":{"id":"https://openalex.org/S4210175523","display_name":"IEEE Transactions on Neural Networks and Learning Systems","issn_l":"2162-237X","issn":["2162-237X","2162-2388"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Neural Networks and Learning Systems","raw_type":"journal-article"},{"id":"pmid:40388282","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/40388282","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on neural networks and learning systems","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W1682403713","https://openalex.org/W1979631293","https://openalex.org/W2194775991","https://openalex.org/W2294710185","https://openalex.org/W2560647685","https://openalex.org/W2579318729","https://openalex.org/W2743151379","https://openalex.org/W2768064608","https://openalex.org/W2806082141","https://openalex.org/W2807363941","https://openalex.org/W2935349488","https://openalex.org/W2942091739","https://openalex.org/W2985954225","https://openalex.org/W3025612445","https://openalex.org/W3042368254","https://openalex.org/W3173775589","https://openalex.org/W3185788529","https://openalex.org/W4210653884","https://openalex.org/W4225999490","https://openalex.org/W4288057808","https://openalex.org/W4323345707","https://openalex.org/W4385245566","https://openalex.org/W4388186067","https://openalex.org/W4390873717","https://openalex.org/W4403323912"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W4386185023"],"abstract_inverted_index":{"Deep":[0],"neural":[1,106,142],"networks":[2,143],"(DNNs)":[3],"have":[4,72],"gained":[5],"considerable":[6],"traction":[7],"in":[8,29,76,123,144,231],"recent":[9,77,138],"years":[10,78],"due":[11],"to":[12,31,34,39,79,156,205,207,235],"the":[13,19,55,89,124,135,145,163,178,194,214,225,232],"unparalleled":[14],"results":[15,168],"they":[16],"gathered.":[17],"However,":[18],"cost":[20],"behind":[21],"training":[22,174,229],"such":[23,103],"sophisticated":[24],"models":[25],"is":[26,113],"resource-intensive,":[27],"resulting":[28],"many":[30],"consider":[32],"DNNs":[33,49],"be":[35,121,181,203],"intellectual":[36],"property":[37],"(IP)":[38],"model":[40,184],"owners.":[41],"In":[42,129],"this":[43,112,130],"era":[44],"of":[45,91,118,126,137,147,196,227],"cloud":[46],"computing,":[47],"high-performance":[48],"are":[50],"often":[51],"deployed":[52],"all":[53],"over":[54],"Internet":[56],"so":[57],"that":[58,114,170],"people":[59],"can":[60,120,180,202],"access":[61],"them":[62],"publicly.":[63],"As":[64],"such,":[65],"DNN":[66],"watermarking":[67],"schemes,":[68,95],"especially":[69],"backdoor-based":[70,127,139],"watermarks,":[71],"been":[73],"actively":[74],"developed":[75],"preserve":[80],"proprietary":[81],"rights.":[82],"Nonetheless,":[83],"there":[84],"lies":[85],"much":[86],"uncertainty":[87],"on":[88,193],"robustness":[90,119],"existing":[92],"backdoor":[93],"watermark":[94,158,179,237],"toward":[96],"both":[97],"adversarial":[98],"attacks":[99],"and":[100,149],"unintended":[101],"means":[102],"as":[104,222,224],"fine-tuning":[105,160,233],"network":[107],"models.":[108],"One":[109],"reason":[110],"for":[111],"no":[115],"complete":[116],"guarantee":[117],"assured":[122],"context":[125],"watermark.":[128],"article,":[131],"we":[132,150],"extensively":[133],"evaluate":[134],"persistence":[136],"watermarks":[140],"within":[141],"scenario":[146],"fine-tuning,":[148,177],"propose/develop":[151],"a":[152],"novel":[153],"data-driven":[154],"idea":[155,226],"restore":[157],"after":[159,176],"without":[161],"exposing":[162],"trigger":[164,197,200],"set.":[165],"Our":[166],"empirical":[167],"show":[169],"by":[171],"solely":[172],"introducing":[173,228],"data":[175,230],"restored":[182],"if":[183],"parameters":[185],"do":[186],"not":[187],"shift":[188],"dramatically":[189],"during":[190],"fine-tuning.":[191],"Depending":[192],"types":[195],"samples":[198],"used,":[199],"accuracy":[201],"reinstated":[204],"up":[206],"100%.":[208],"This":[209],"study":[210],"further":[211],"explores":[212],"how":[213],"restoration":[215],"process":[216],"works":[217],"using":[218],"loss":[219],"landscape":[220],"visualization,":[221],"well":[223],"stage":[234],"alleviate":[236],"vanishing.":[238]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
