{"id":"https://openalex.org/W7138907550","doi":"https://doi.org/10.1609/aaai.v40i42.40915","title":"Hashed Watermark as a Filter: A Unified Defense Against Forging and Overwriting Attacks in Neural Network Watermarking","display_name":"Hashed Watermark as a Filter: A Unified Defense Against Forging and Overwriting Attacks in Neural Network Watermarking","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7138907550","doi":"https://doi.org/10.1609/aaai.v40i42.40915"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i42.40915","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i42.40915","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://doi.org/10.1609/aaai.v40i42.40915","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Yuan Yao","orcid":null},"institutions":[{"id":"https://openalex.org/I4210130112","display_name":"China Academy of Information and Communications Technology","ror":"https://ror.org/038dte259","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210130112","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yuan Yao","raw_affiliation_strings":["Beijing Teleinfo Technology Company Ltd., China Academy of Information and Communications Technology"],"affiliations":[{"raw_affiliation_string":"Beijing Teleinfo Technology Company Ltd., China Academy of Information and Communications Technology","institution_ids":["https://openalex.org/I4210130112"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112998118","display_name":"Jin Mo Song","orcid":null},"institutions":[{"id":"https://openalex.org/I41198531","display_name":"Nanjing University of Posts and Telecommunications","ror":"https://ror.org/043bpky34","country_code":"CN","type":"education","lineage":["https://openalex.org/I41198531"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jin Song","raw_affiliation_strings":["School of Computer Science, Nanjing University of Posts and Telecommunications"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Nanjing University of Posts and Telecommunications","institution_ids":["https://openalex.org/I41198531"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5129839460","display_name":"Jian Jin","orcid":null},"institutions":[{"id":"https://openalex.org/I4210130112","display_name":"China Academy of Information and Communications Technology","ror":"https://ror.org/038dte259","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210130112","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jian Jin","raw_affiliation_strings":["Research Institute of Industrial Internet of Things, China Academy of information and communications technology"],"affiliations":[{"raw_affiliation_string":"Research Institute of Industrial Internet of Things, China Academy of information and communications technology","institution_ids":["https://openalex.org/I4210130112"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I4210130112"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.75636545,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"40","issue":"42","first_page":"35994","last_page":"36002"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9175000190734863,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9175000190734863,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.014000000432133675,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.008500000461935997,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.8348000049591064},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8241000175476074},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6557999849319458},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.5922999978065491},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5914000272750854},{"id":"https://openalex.org/keywords/hash-function","display_name":"Hash function","score":0.576200008392334},{"id":"https://openalex.org/keywords/forging","display_name":"Forging","score":0.5282999873161316},{"id":"https://openalex.org/keywords/bitmap","display_name":"Bitmap","score":0.4422000050544739},{"id":"https://openalex.org/keywords/histogram","display_name":"Histogram","score":0.40549999475479126}],"concepts":[{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.8348000049591064},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8241000175476074},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7908999919891357},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6557999849319458},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6473000049591064},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.5922999978065491},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5914000272750854},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.576200008392334},{"id":"https://openalex.org/C96494537","wikidata":"https://www.wikidata.org/wiki/Q193057","display_name":"Forging","level":2,"score":0.5282999873161316},{"id":"https://openalex.org/C3115412","wikidata":"https://www.wikidata.org/wiki/Q1194708","display_name":"Bitmap","level":2,"score":0.4422000050544739},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.44020000100135803},{"id":"https://openalex.org/C53533937","wikidata":"https://www.wikidata.org/wiki/Q185020","display_name":"Histogram","level":3,"score":0.40549999475479126},{"id":"https://openalex.org/C70437156","wikidata":"https://www.wikidata.org/wiki/Q7228652","display_name":"Pooling","level":2,"score":0.3912999927997589},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3555999994277954},{"id":"https://openalex.org/C3073032","wikidata":"https://www.wikidata.org/wiki/Q15912075","display_name":"Information hiding","level":3,"score":0.350600004196167},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3456999957561493},{"id":"https://openalex.org/C48372109","wikidata":"https://www.wikidata.org/wiki/Q3913","display_name":"Binary number","level":2,"score":0.3269999921321869},{"id":"https://openalex.org/C106131492","wikidata":"https://www.wikidata.org/wiki/Q3072260","display_name":"Filter (signal processing)","level":2,"score":0.3163999915122986},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.31470000743865967},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.31369999051094055},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.31209999322891235},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.3025999963283539},{"id":"https://openalex.org/C2781137444","wikidata":"https://www.wikidata.org/wiki/Q237105","display_name":"Sharpening","level":2,"score":0.29589998722076416},{"id":"https://openalex.org/C9417928","wikidata":"https://www.wikidata.org/wiki/Q1070689","display_name":"Image processing","level":3,"score":0.2806999981403351},{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.2614000141620636},{"id":"https://openalex.org/C155032097","wikidata":"https://www.wikidata.org/wiki/Q798503","display_name":"Backpropagation","level":3,"score":0.2606000006198883},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.259799987077713},{"id":"https://openalex.org/C42781572","wikidata":"https://www.wikidata.org/wiki/Q1250322","display_name":"Digital image","level":4,"score":0.2572999894618988},{"id":"https://openalex.org/C160633673","wikidata":"https://www.wikidata.org/wiki/Q355198","display_name":"Pixel","level":2,"score":0.25679999589920044},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.2563000023365021}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i42.40915","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i42.40915","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i42.40915","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i42.40915","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"As":[0],"valuable":[1],"digital":[2],"assets,":[3],"deep":[4],"neural":[5,12,129],"networks":[6],"necessitate":[7],"robust":[8,51,102],"ownership":[9],"protection,":[10],"positioning":[11],"network":[13,130],"watermarking":[14],"(NNW)":[15],"as":[16,79,150],"a":[17,50,55,62,72,80,101,147,151],"promising":[18],"solution.":[19],"Among":[20],"various":[21,128],"NNW":[22],"approaches,":[23],"weight-based":[24],"methods":[25],"are":[26],"favored":[27],"for":[28,87],"their":[29],"simplicity":[30],"and":[31,40,107,118,141,159,165,173],"practicality;":[32],"however,":[33],"they":[34],"remain":[35],"generally":[36],"vulnerable":[37],"to":[38,65,82,115],"forging":[39,106],"overwriting":[41,108],"attacks.":[42,109,120],"To":[43],"address":[44],"those":[45],"challenges,":[46],"we":[47,60,155],"propose":[48],"*NeuralMark*,":[49],"method":[52],"built":[53],"around":[54],"*hashed":[56],"watermark":[57,70,149],"filter*.":[58],"Specifically,":[59],"utilize":[61],"hash":[63],"function":[64],"generate":[66],"an":[67],"irreversible":[68],"binary":[69],"from":[71],"secret":[73],"key,":[74],"which":[75],"is":[76,112],"then":[77],"used":[78],"filter":[81],"select":[83],"the":[84,93,97,143],"model":[85],"parameters":[86,95],"embedding.":[88],"This":[89],"design":[90],"cleverly":[91],"intertwines":[92],"embedding":[94],"with":[96],"hashed":[98,148],"watermark,":[99],"providing":[100],"defense":[103],"against":[104],"both":[105],"Average":[110],"pooling":[111],"also":[113],"incorporated":[114],"resist":[116],"fine-tuning":[117],"pruning":[119],"Furthermore,":[121],"it":[122],"can":[123],"be":[124],"seamlessly":[125],"integrated":[126],"into":[127],"architectures,":[131,167],"ensuring":[132],"broad":[133],"applicability.":[134],"We":[135],"theoretically":[136],"analyze":[137],"its":[138,157],"security":[139],"boundary":[140],"highlight":[142],"necessity":[144],"of":[145],"using":[146],"filtering":[152],"mechanism.":[153],"Empirically,":[154],"demonstrate":[156],"effectiveness":[158],"robustness":[160],"across":[161],"13":[162],"distinct":[163],"Convolutional":[164],"Transformer":[166],"covering":[168],"five":[169],"image":[170],"classification":[171],"tasks":[172],"one":[174],"text":[175],"generation":[176],"task.":[177]},"counts_by_year":[],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2026-03-20T00:00:00"}
