{"id":"https://openalex.org/W4387967949","doi":"https://doi.org/10.1145/3581783.3612515","title":"Deep Neural Network Watermarking against Model Extraction Attack","display_name":"Deep Neural Network Watermarking against Model Extraction Attack","publication_year":2023,"publication_date":"2023-10-26","ids":{"openalex":"https://openalex.org/W4387967949","doi":"https://doi.org/10.1145/3581783.3612515"},"language":"en","primary_location":{"id":"doi:10.1145/3581783.3612515","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3581783.3612515","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5075582592","display_name":"J. Tan","orcid":"https://orcid.org/0000-0002-7267-0711"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Jingxuan Tan","raw_affiliation_strings":["School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060167465","display_name":"Nan Zhong","orcid":"https://orcid.org/0000-0002-0868-019X"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Nan Zhong","raw_affiliation_strings":["School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054324316","display_name":"Zhenxing Qian","orcid":"https://orcid.org/0000-0003-1622-0561"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhenxing Qian","raw_affiliation_strings":["School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101889358","display_name":"Xinpeng Zhang","orcid":"https://orcid.org/0000-0002-0212-3501"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinpeng Zhang","raw_affiliation_strings":["School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100359820","display_name":"Sheng Li","orcid":"https://orcid.org/0000-0002-7589-9554"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Sheng Li","raw_affiliation_strings":["School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Fudan University &amp; Key Laboratory of Culture &amp; Tourism Intelligent Computing, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5075582592"],"corresponding_institution_ids":["https://openalex.org/I24943067"],"apc_list":null,"apc_paid":null,"fwci":4.1179,"has_fulltext":false,"cited_by_count":24,"citation_normalized_percentile":{"value":0.95206,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1588","last_page":"1597"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9861000180244446,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9781000018119812,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8246701955795288},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8097469806671143},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.7703944444656372},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.665939450263977},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6411988139152527},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.6112500429153442},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5677769780158997},{"id":"https://openalex.org/keywords/fine-tuning","display_name":"Fine-tuning","score":0.5116322636604309},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5063275098800659},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.47789180278778076},{"id":"https://openalex.org/keywords/shadow","display_name":"Shadow (psychology)","score":0.4681444764137268},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.46607470512390137},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.46204349398612976},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.43238192796707153},{"id":"https://openalex.org/keywords/autoencoder","display_name":"Autoencoder","score":0.4270758330821991},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.406194269657135},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.25467783212661743}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8246701955795288},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8097469806671143},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.7703944444656372},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.665939450263977},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6411988139152527},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.6112500429153442},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5677769780158997},{"id":"https://openalex.org/C157524613","wikidata":"https://www.wikidata.org/wiki/Q2828883","display_name":"Fine-tuning","level":2,"score":0.5116322636604309},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5063275098800659},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.47789180278778076},{"id":"https://openalex.org/C117797892","wikidata":"https://www.wikidata.org/wiki/Q286363","display_name":"Shadow (psychology)","level":2,"score":0.4681444764137268},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.46607470512390137},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.46204349398612976},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.43238192796707153},{"id":"https://openalex.org/C101738243","wikidata":"https://www.wikidata.org/wiki/Q786435","display_name":"Autoencoder","level":3,"score":0.4270758330821991},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.406194269657135},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.25467783212661743},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C542102704","wikidata":"https://www.wikidata.org/wiki/Q183257","display_name":"Psychotherapist","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3581783.3612515","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3581783.3612515","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1961232708","display_name":null,"funder_award_id":"U22B2047","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2087396116","display_name":null,"funder_award_id":"China","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2429589907","display_name":null,"funder_award_id":"U1936214","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2724549297","display_name":null,"funder_award_id":"62072114","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3317480652","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3935748781","display_name":null,"funder_award_id":"U20A20178","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5994120800","display_name":null,"funder_award_id":"Natural","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6435596466","display_name":null,"funder_award_id":"U20B2051","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7896782678","display_name":null,"funder_award_id":"U20A2017","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8400801390","display_name":null,"funder_award_id":"U20A201","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":26,"referenced_works":["https://openalex.org/W2194775991","https://openalex.org/W2579318729","https://openalex.org/W2603766943","https://openalex.org/W2768064608","https://openalex.org/W2806082141","https://openalex.org/W2935349488","https://openalex.org/W2942091739","https://openalex.org/W2963163009","https://openalex.org/W2963303354","https://openalex.org/W2964128659","https://openalex.org/W2969695741","https://openalex.org/W2973414778","https://openalex.org/W2997146418","https://openalex.org/W2997717738","https://openalex.org/W3096093113","https://openalex.org/W3102733833","https://openalex.org/W3135872251","https://openalex.org/W3156011647","https://openalex.org/W3156309620","https://openalex.org/W3173775589","https://openalex.org/W3175133087","https://openalex.org/W3203430276","https://openalex.org/W3206880386","https://openalex.org/W4226014375","https://openalex.org/W4288057808","https://openalex.org/W4323345707"],"related_works":["https://openalex.org/W2137394636","https://openalex.org/W2358993821","https://openalex.org/W1516446231","https://openalex.org/W2098152888","https://openalex.org/W1559740347","https://openalex.org/W2040356834","https://openalex.org/W2385289568","https://openalex.org/W2381486749","https://openalex.org/W1514507288","https://openalex.org/W2183032046"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"network":[2],"(DNN)":[3],"watermarking":[4,22,78],"is":[5,133,231],"an":[6,84],"emerging":[7],"technique":[8],"to":[9,27,50,62,98,102,120,136,154,164,233],"protect":[10],"the":[11,36,42,60,100,114,117,122,156,167,185],"intellectual":[12],"property":[13],"of":[14,41,94,116,124,144],"deep":[15],"learning":[16],"models.":[17,127,140],"At":[18],"present,":[19],"many":[20],"DNN":[21,77],"algorithms":[23],"have":[24],"been":[25],"proposed":[26],"achieve":[28],"provenance":[29],"verification":[30],"by":[31,89,113],"embedding":[32,182,184],"identify":[33],"information":[34],"into":[35],"internals":[37],"or":[38,66,189,219],"prediction":[39,115],"behaviors":[40,123],"host":[43,118,168],"model.":[44],"However,":[45],"most":[46],"methods":[47,206],"are":[48],"vulnerable":[49],"model":[51,61,103,111,119,132,169,209,235,241],"extraction":[52,210],"attacks,":[53],"where":[54],"attackers":[55],"collect":[56],"output":[57],"labels":[58],"from":[59,190],"train":[63,107],"a":[64,67,75,92,108,129,148,152],"surrogate":[65,126],"replica.":[68],"To":[69],"address":[70],"this":[71,142],"issue,":[72],"we":[73,106,150],"present":[74],"novel":[76],"approach,":[79],"named":[80],"SSW,":[81],"which":[82],"constructs":[83],"adaptive":[85],"trigger":[86,157,214],"set":[87,215],"progressively":[88],"optimizing":[90],"over":[91],"pair":[93,143],"symmetric":[95],"shadow":[96,110,131,145],"models":[97,146],"enhance":[99],"robustness":[101],"extraction.":[104],"Precisely,":[105],"positive":[109],"supervised":[112],"mimic":[121],"potential":[125],"Additionally,":[128],"negative":[130],"normally":[134],"trained":[135],"imitate":[137],"irrelevant":[138],"independent":[139],"Using":[141],"as":[147],"reference,":[149],"design":[151],"strategy":[153],"update":[155],"samples":[158],"appropriately":[159],"such":[160],"that":[161,200,228],"they":[162],"tend":[163],"persist":[165],"in":[166,212],"and":[170,240],"its":[171],"stolen":[172],"copies.":[173],"Moreover,":[174],"our":[175,201,229],"method":[176,230],"could":[177],"well":[178],"support":[179],"two":[180],"specific":[181],"schemes:":[183],"watermark":[186],"via":[187],"fine-tuning":[188,239],"scratch.":[191],"Our":[192],"extensive":[193],"experimental":[194],"results":[195,225],"on":[196],"popular":[197],"datasets":[198],"demonstrate":[199],"SSW":[202],"approach":[203],"outperforms":[204],"state-of-the-art":[205],"against":[207],"various":[208],"attacks":[211],"whether":[213],"classification":[216],"accuracy":[217],"based":[218,222],"hypothesis":[220],"test":[221],"verification.":[223],"The":[224],"also":[226],"show":[227],"robust":[232],"common":[234],"modification":[236],"schemes":[237],"including":[238],"compression.":[242]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":15},{"year":2024,"cited_by_count":7}],"updated_date":"2026-04-18T07:56:08.524223","created_date":"2025-10-10T00:00:00"}
