{"id":"https://openalex.org/W4383199672","doi":"https://doi.org/10.1145/3606274.3606279","title":"Did You Train on My Dataset? Towards Public Dataset Protection with CleanLabel Backdoor Watermarking","display_name":"Did You Train on My Dataset? Towards Public Dataset Protection with CleanLabel Backdoor Watermarking","publication_year":2023,"publication_date":"2023-06-22","ids":{"openalex":"https://openalex.org/W4383199672","doi":"https://doi.org/10.1145/3606274.3606279"},"language":"en","primary_location":{"id":"doi:10.1145/3606274.3606279","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3606274.3606279","pdf_url":null,"source":{"id":"https://openalex.org/S4210176598","display_name":"ACM SIGKDD Explorations Newsletter","issn_l":"1931-0145","issn":["1931-0145","1931-0153"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM SIGKDD Explorations Newsletter","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101660251","display_name":"Ruixiang Tang","orcid":"https://orcid.org/0000-0001-6476-2336"},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Ruixiang Tang","raw_affiliation_strings":["Rice University, TX, USA"],"affiliations":[{"raw_affiliation_string":"Rice University, TX, USA","institution_ids":["https://openalex.org/I74775410"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5040574435","display_name":"Qizhang Feng","orcid":"https://orcid.org/0000-0002-2574-0270"},"institutions":[{"id":"https://openalex.org/I91045830","display_name":"Texas A&M University","ror":"https://ror.org/01f5ytq51","country_code":"US","type":"education","lineage":["https://openalex.org/I91045830"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qizhang Feng","raw_affiliation_strings":["Texas A&amp;M University, TX, USA"],"affiliations":[{"raw_affiliation_string":"Texas A&amp;M University, TX, USA","institution_ids":["https://openalex.org/I91045830"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5007489034","display_name":"Ninghao Liu","orcid":"https://orcid.org/0000-0002-9170-2424"},"institutions":[{"id":"https://openalex.org/I165733156","display_name":"University of Georgia","ror":"https://ror.org/00te3t702","country_code":"US","type":"education","lineage":["https://openalex.org/I165733156"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ninghao Liu","raw_affiliation_strings":["University of Georgia, GA, USA"],"affiliations":[{"raw_affiliation_string":"University of Georgia, GA, USA","institution_ids":["https://openalex.org/I165733156"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5106406581","display_name":"Fan Yang","orcid":"https://orcid.org/0009-0008-1466-9262"},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fan Yang","raw_affiliation_strings":["Rice University, TX, USA"],"affiliations":[{"raw_affiliation_string":"Rice University, TX, USA","institution_ids":["https://openalex.org/I74775410"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5068477431","display_name":"Xia Hu","orcid":"https://orcid.org/0000-0003-2234-3226"},"institutions":[{"id":"https://openalex.org/I74775410","display_name":"Rice University","ror":"https://ror.org/008zs3103","country_code":"US","type":"education","lineage":["https://openalex.org/I74775410"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xia Hu","raw_affiliation_strings":["Rice University, TX, USA"],"affiliations":[{"raw_affiliation_string":"Rice University, TX, USA","institution_ids":["https://openalex.org/I74775410"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5101660251"],"corresponding_institution_ids":["https://openalex.org/I74775410"],"apc_list":null,"apc_paid":null,"fwci":5.9937,"has_fulltext":false,"cited_by_count":34,"citation_normalized_percentile":{"value":0.97082274,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":"25","issue":"1","first_page":"43","last_page":"53"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9867092370986938},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8772252798080444},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8485288023948669},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.7263367176055908},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5830366611480713},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.5674853324890137},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5399837493896484},{"id":"https://openalex.org/keywords/function","display_name":"Function (biology)","score":0.5290101170539856},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.49536097049713135},{"id":"https://openalex.org/keywords/data-set","display_name":"Data set","score":0.4490804672241211},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.44595953822135925},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.41656023263931274},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4129270613193512},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.382111519575119},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.36640000343322754},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.09589609503746033}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9867092370986938},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8772252798080444},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8485288023948669},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.7263367176055908},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5830366611480713},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.5674853324890137},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5399837493896484},{"id":"https://openalex.org/C14036430","wikidata":"https://www.wikidata.org/wiki/Q3736076","display_name":"Function (biology)","level":2,"score":0.5290101170539856},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.49536097049713135},{"id":"https://openalex.org/C58489278","wikidata":"https://www.wikidata.org/wiki/Q1172284","display_name":"Data set","level":2,"score":0.4490804672241211},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.44595953822135925},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.41656023263931274},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4129270613193512},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.382111519575119},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.36640000343322754},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.09589609503746033},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C78458016","wikidata":"https://www.wikidata.org/wiki/Q840400","display_name":"Evolutionary biology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3606274.3606279","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3606274.3606279","pdf_url":null,"source":{"id":"https://openalex.org/S4210176598","display_name":"ACM SIGKDD Explorations Newsletter","issn_l":"1931-0145","issn":["1931-0145","1931-0153"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM SIGKDD Explorations Newsletter","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W2137394636","https://openalex.org/W2358993821","https://openalex.org/W1516446231","https://openalex.org/W2098152888","https://openalex.org/W1559740347","https://openalex.org/W2040356834","https://openalex.org/W2385289568","https://openalex.org/W2381486749","https://openalex.org/W1514507288","https://openalex.org/W2183032046"],"abstract_inverted_index":{"The":[0],"huge":[1],"supporting":[2],"training":[3,123],"data":[4,25,120],"on":[5,177,194],"the":[6,14,30,72,77,106,122,161,167,185],"Internet":[7],"has":[8],"been":[9],"a":[10,49,56,65,83,97,127,145,159,210],"key":[11],"factor":[12],"in":[13,130],"success":[15],"of":[16,23,33,68,205],"deep":[17],"learning":[18,78],"models.":[19],"However,":[20],"this":[21,45,141],"abundance":[22],"public-available":[24],"also":[26,199],"raises":[27],"concerns":[28],"about":[29],"unauthorized":[31],"exploitation":[32],"datasets":[34,182,190],"for":[35,59],"commercial":[36],"purposes,":[37],"which":[38],"is":[39],"forbidden":[40],"by":[41,87,135],"dataset":[42,107],"licenses.":[43],"In":[44],"paper,":[46],"we":[47,143],"propose":[48],"backdoor-based":[50],"watermarking":[51,69,148,162,206,212,217],"approach":[52,75],"that":[53,104,150,184,201,215],"serves":[54],"as":[55,96],"general":[57],"framework":[58,149,187],"safeguarding":[60],"publicavailable":[61],"data.":[62],"By":[63],"inserting":[64],"small":[66],"number":[67],"samples":[70,163,207,218],"into":[71],"dataset,":[73],"our":[74,216],"enables":[76],"model":[79],"to":[80,99,121,126,154,173],"implicitly":[81],"learn":[82],"secret":[84],"function":[85,91,213],"set":[86],"defenders.":[88],"This":[89],"hidden":[90],"can":[92,208],"then":[93],"be":[94],"used":[95],"watermark":[98],"track":[100],"down":[101],"third-party":[102],"models":[103],"use":[105],"illegally.":[108],"Unfortunately,":[109],"existing":[110],"backdoor":[111,147],"insertion":[112],"methods":[113],"often":[114],"entail":[115],"adding":[116,202],"arbitrary":[117],"and":[118,132,180,214,221],"mislabeled":[119,156],"set,":[124],"leading":[125],"significant":[128],"drop":[129],"performance":[131],"easy":[133],"detection":[134,137],"anomaly":[136],"algorithms.":[138],"To":[139],"overcome":[140],"challenge,":[142],"introduce":[144],"clean-label":[146],"uses":[151],"imperceptible":[152],"perturbations":[153],"replace":[155],"samples.":[157],"As":[158],"result,":[160],"remain":[164],"consistent":[165],"with":[166,191],"original":[168,195],"labels,":[169],"making":[170],"them":[171],"difficult":[172],"detect.":[174],"Our":[175],"experiments":[176],"text,":[178],"image,":[179],"audio":[181],"demonstrate":[183],"proposed":[186],"effectively":[188],"safeguards":[189],"minimal":[192],"impact":[193],"task":[196],"performance.":[197],"We":[198],"show":[200],"just":[203],"1%":[204],"inject":[209],"traceable":[211],"are":[219],"stealthy":[220],"look":[222],"benign":[223],"upon":[224],"visual":[225],"inspection.":[226]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":21},{"year":2024,"cited_by_count":10},{"year":2023,"cited_by_count":2}],"updated_date":"2026-03-17T09:09:15.849793","created_date":"2025-10-10T00:00:00"}
