{"id":"https://openalex.org/W3192504716","doi":"https://doi.org/10.24963/ijcai.2021/500","title":"Fine-tuning Is Not Enough: A Simple yet Effective Watermark Removal Attack for DNN Models","display_name":"Fine-tuning Is Not Enough: A Simple yet Effective Watermark Removal Attack for DNN Models","publication_year":2021,"publication_date":"2021-08-01","ids":{"openalex":"https://openalex.org/W3192504716","doi":"https://doi.org/10.24963/ijcai.2021/500","mag":"3192504716"},"language":"en","primary_location":{"id":"doi:10.24963/ijcai.2021/500","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2021/500","pdf_url":"https://www.ijcai.org/proceedings/2021/0500.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.ijcai.org/proceedings/2021/0500.pdf","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5073264981","display_name":"Shangwei Guo","orcid":"https://orcid.org/0000-0002-6443-5308"},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Shangwei Guo","raw_affiliation_strings":["Chongqing University","College of Computer Science, Chongqing University, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chongqing University","institution_ids":["https://openalex.org/I158842170"]},{"raw_affiliation_string":"College of Computer Science, Chongqing University, China","institution_ids":["https://openalex.org/I158842170"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101591101","display_name":"Tianwei Zhang","orcid":"https://orcid.org/0000-0001-6595-6650"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Tianwei Zhang","raw_affiliation_strings":["Nanyang Technological University","School of Computer Science and Engineering, Nanyang Technological University, Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Nanyang Technological University","institution_ids":["https://openalex.org/I172675005"]},{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019692903","display_name":"Han Qiu","orcid":"https://orcid.org/0000-0003-2678-8070"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Han Qiu","raw_affiliation_strings":["Tsinghua University","Institute for Network Sciences and Cyberspace, Tsinghua University, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tsinghua University","institution_ids":["https://openalex.org/I99065089"]},{"raw_affiliation_string":"Institute for Network Sciences and Cyberspace, Tsinghua University, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025846619","display_name":"Yi Zeng","orcid":"https://orcid.org/0000-0002-9595-9091"},"institutions":[{"id":"https://openalex.org/I859038795","display_name":"Virginia Tech","ror":"https://ror.org/02smfhw86","country_code":"US","type":"education","lineage":["https://openalex.org/I859038795"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yi Zeng","raw_affiliation_strings":["Virginia Tech","The Bradley Department of Electronic and Computer Engineering, Virginia Tech Blacksburg, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Virginia Tech","institution_ids":["https://openalex.org/I859038795"]},{"raw_affiliation_string":"The Bradley Department of Electronic and Computer Engineering, Virginia Tech Blacksburg, USA","institution_ids":["https://openalex.org/I859038795"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079461118","display_name":"Tao Xiang","orcid":"https://orcid.org/0000-0002-9439-4623"},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tao Xiang","raw_affiliation_strings":["Chongqing University","College of Computer Science, Chongqing University, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chongqing University","institution_ids":["https://openalex.org/I158842170"]},{"raw_affiliation_string":"College of Computer Science, Chongqing University, China","institution_ids":["https://openalex.org/I158842170"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100355692","display_name":"Yang Liu","orcid":"https://orcid.org/0000-0001-7300-9215"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Yang Liu","raw_affiliation_strings":["Nanyang Technology University","School of Computer Science and Engineering, Nanyang Technological University, Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Nanyang Technology University","institution_ids":[]},{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5073264981"],"corresponding_institution_ids":["https://openalex.org/I158842170"],"apc_list":null,"apc_paid":null,"fwci":3.0781,"has_fulltext":false,"cited_by_count":29,"citation_normalized_percentile":{"value":0.92837816,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"3635","last_page":"3641"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9884999990463257,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.9441779255867004},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.8963242769241333},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7629927396774292},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.696260929107666},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.6430581212043762},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.6186227202415466},{"id":"https://openalex.org/keywords/memorization","display_name":"Memorization","score":0.5432272553443909},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4749160706996918},{"id":"https://openalex.org/keywords/transformation","display_name":"Transformation (genetics)","score":0.47133517265319824},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.4690924882888794},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.45818060636520386},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.42958009243011475},{"id":"https://openalex.org/keywords/simple","display_name":"Simple (philosophy)","score":0.42836111783981323},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.35448741912841797},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.14013755321502686},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.11530795693397522}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.9441779255867004},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.8963242769241333},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7629927396774292},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.696260929107666},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.6430581212043762},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.6186227202415466},{"id":"https://openalex.org/C30038468","wikidata":"https://www.wikidata.org/wiki/Q4354775","display_name":"Memorization","level":2,"score":0.5432272553443909},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4749160706996918},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.47133517265319824},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.4690924882888794},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.45818060636520386},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.42958009243011475},{"id":"https://openalex.org/C2780586882","wikidata":"https://www.wikidata.org/wiki/Q7520643","display_name":"Simple (philosophy)","level":2,"score":0.42836111783981323},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.35448741912841797},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.14013755321502686},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.11530795693397522},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C145420912","wikidata":"https://www.wikidata.org/wiki/Q853077","display_name":"Mathematics education","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.24963/ijcai.2021/500","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2021/500","pdf_url":"https://www.ijcai.org/proceedings/2021/0500.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.24963/ijcai.2021/500","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2021/500","pdf_url":"https://www.ijcai.org/proceedings/2021/0500.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/12","score":0.4300000071525574,"display_name":"Responsible consumption and production"}],"awards":[{"id":"https://openalex.org/G1546930127","display_name":null,"funder_award_id":"U20A20176","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G160155416","display_name":null,"funder_award_id":"NRF2018NCR-NCR009-0001","funder_id":"https://openalex.org/F4320320671","funder_display_name":"National Research Foundation"},{"id":"https://openalex.org/G2640896872","display_name":null,"funder_award_id":"NRFI06-2020-0022","funder_id":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore"},{"id":"https://openalex.org/G3805874868","display_name":null,"funder_award_id":"cstc2019jcyjjqX0026","funder_id":"https://openalex.org/F4320323172","funder_display_name":"Natural Science Foundation of Chongqing"},{"id":"https://openalex.org/G4045071619","display_name":null,"funder_award_id":"NRF2018NCR-NCR005-0001","funder_id":"https://openalex.org/F4320320671","funder_display_name":"National Research Foundation"},{"id":"https://openalex.org/G4382255046","display_name":null,"funder_award_id":"NRF2018NCR-NSOE003-0001","funder_id":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore"},{"id":"https://openalex.org/G4921399682","display_name":null,"funder_award_id":"NRF2018NCR-NCR005-0001","funder_id":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore"},{"id":"https://openalex.org/G5928885788","display_name":null,"funder_award_id":"NRF2018NCR-NCR009-0001","funder_id":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore"},{"id":"https://openalex.org/G6828898563","display_name":null,"funder_award_id":"NRF2018NCR-NSOE003-0001","funder_id":"https://openalex.org/F4320320671","funder_display_name":"National Research Foundation"},{"id":"https://openalex.org/G724036087","display_name":null,"funder_award_id":"62072062","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320320671","display_name":"National Research Foundation","ror":"https://ror.org/05s0g1g46"},{"id":"https://openalex.org/F4320320709","display_name":"National Research Foundation Singapore","ror":"https://ror.org/03cpyc314"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320323172","display_name":"Natural Science Foundation of Chongqing","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3192504716.pdf","grobid_xml":"https://content.openalex.org/works/W3192504716.grobid-xml"},"referenced_works_count":24,"referenced_works":["https://openalex.org/W2113640817","https://openalex.org/W2124890704","https://openalex.org/W2194775991","https://openalex.org/W2579318729","https://openalex.org/W2607219512","https://openalex.org/W2768064608","https://openalex.org/W2788262295","https://openalex.org/W2806082141","https://openalex.org/W2905327972","https://openalex.org/W2949736877","https://openalex.org/W2962933288","https://openalex.org/W2963384482","https://openalex.org/W2964128659","https://openalex.org/W2973539365","https://openalex.org/W2986013765","https://openalex.org/W2997717738","https://openalex.org/W3096024389","https://openalex.org/W3102111060","https://openalex.org/W3156793535","https://openalex.org/W3158240034","https://openalex.org/W3184974140","https://openalex.org/W4288322434","https://openalex.org/W4288404646","https://openalex.org/W4294506858"],"related_works":["https://openalex.org/W2137394636","https://openalex.org/W2358993821","https://openalex.org/W1516446231","https://openalex.org/W2098152888","https://openalex.org/W1559740347","https://openalex.org/W2040356834","https://openalex.org/W2080353903","https://openalex.org/W2385289568","https://openalex.org/W2381486749","https://openalex.org/W1514507288"],"abstract_inverted_index":{"Watermarking":[0],"has":[1],"become":[2],"the":[3,7,16,63,88,94,106,118,152],"tendency":[4],"in":[5],"protecting":[6],"intellectual":[8],"property":[9],"of":[10,60,90,154],"DNN":[11],"models.":[12],"Recent":[13],"works,":[14],"from":[15,55],"adversary's":[17],"perspective,":[18],"attempted":[19],"to":[20,93,104,150],"subvert":[21],"watermarking":[22,119,134],"mechanisms":[23],"by":[24,74],"designing":[25],"watermark":[26,52,95,147],"removal":[27,53],"attacks.":[28],"However,":[29],"these":[30],"attacks":[31],"mainly":[32],"adopted":[33],"sophisticated":[34],"fine-tuning":[35,62,102],"techniques,":[36],"which":[37,82],"have":[38],"certain":[39],"fatal":[40],"drawbacks":[41],"or":[42,115],"unrealistic":[43],"assumptions.":[44],"In":[45],"this":[46],"paper,":[47],"we":[48,66,145],"propose":[49,146],"a":[50,56,68,100],"novel":[51],"attack":[54,130],"different":[57],"perspective.":[58],"Instead":[59],"just":[61],"watermarked":[64,91],"models,":[65],"design":[67],"simple":[69],"yet":[70],"powerful":[71],"transformation":[72],"algorithm":[73],"combining":[75],"imperceptible":[76],"pattern":[77],"embedding":[78],"and":[79,85],"spatial-level":[80],"transformations,":[81],"can":[83,131],"effectively":[84],"blindly":[86],"destroy":[87],"memorization":[89],"models":[92],"samples.":[96],"We":[97],"also":[98],"introduce":[99],"lightweight":[101],"strategy":[103],"preserve":[105],"model":[107],"performance.":[108],"Our":[109],"solution":[110],"requires":[111],"much":[112],"less":[113],"resource":[114],"knowledge":[116],"about":[117],"scheme":[120],"than":[121],"prior":[122],"works.":[123],"Extensive":[124],"experimental":[125],"results":[126],"indicate":[127],"that":[128],"our":[129,143],"bypass":[132],"state-of-the-art":[133],"solutions":[135],"with":[136],"very":[137],"high":[138],"success":[139],"rates.":[140],"Based":[141],"on":[142],"attack,":[144],"augmentation":[148],"techniques":[149],"enhance":[151],"robustness":[153],"existing":[155],"watermarks.":[156]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":11},{"year":2022,"cited_by_count":5},{"year":2021,"cited_by_count":1}],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2025-10-10T00:00:00"}
