{"id":"https://openalex.org/W4409045452","doi":"https://doi.org/10.3390/make7020032","title":"RoSe-Mix: Robust and Secure Deep Neural Network Watermarking in Black-Box Settings via Image Mixup","display_name":"RoSe-Mix: Robust and Secure Deep Neural Network Watermarking in Black-Box Settings via Image Mixup","publication_year":2025,"publication_date":"2025-03-30","ids":{"openalex":"https://openalex.org/W4409045452","doi":"https://doi.org/10.3390/make7020032"},"language":"en","primary_location":{"id":"doi:10.3390/make7020032","is_oa":true,"landing_page_url":"https://doi.org/10.3390/make7020032","pdf_url":"https://www.mdpi.com/2504-4990/7/2/32/pdf?version=1743500302","source":{"id":"https://openalex.org/S4210213891","display_name":"Machine Learning and Knowledge Extraction","issn_l":"2504-4990","issn":["2504-4990"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Machine Learning and Knowledge Extraction","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/2504-4990/7/2/32/pdf?version=1743500302","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5116866377","display_name":"Tamara El Hajjar","orcid":null},"institutions":[{"id":"https://openalex.org/I154526488","display_name":"Inserm","ror":"https://ror.org/02vjkv261","country_code":"FR","type":"government","lineage":["https://openalex.org/I154526488"]},{"id":"https://openalex.org/I4210127572","display_name":"IMT Atlantique","ror":"https://ror.org/030hj3061","country_code":"FR","type":"education","lineage":["https://openalex.org/I205703379","https://openalex.org/I4210127572"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Tamara El Hajjar","raw_affiliation_strings":["IMT Atlantique, Inserm UMR 1101, 29200 Brest, France"],"affiliations":[{"raw_affiliation_string":"IMT Atlantique, Inserm UMR 1101, 29200 Brest, France","institution_ids":["https://openalex.org/I4210127572","https://openalex.org/I154526488"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043935032","display_name":"Mohammed Lansari","orcid":"https://orcid.org/0009-0004-8025-5587"},"institutions":[{"id":"https://openalex.org/I154526488","display_name":"Inserm","ror":"https://ror.org/02vjkv261","country_code":"FR","type":"government","lineage":["https://openalex.org/I154526488"]},{"id":"https://openalex.org/I4210127572","display_name":"IMT Atlantique","ror":"https://ror.org/030hj3061","country_code":"FR","type":"education","lineage":["https://openalex.org/I205703379","https://openalex.org/I4210127572"]},{"id":"https://openalex.org/I4210140930","display_name":"Thales (France)","ror":"https://ror.org/04emwm605","country_code":"FR","type":"company","lineage":["https://openalex.org/I4210140930"]}],"countries":["FR"],"is_corresponding":true,"raw_author_name":"Mohammed Lansari","raw_affiliation_strings":["CortAIx Labs, Thales, 91120 Palaiseau, France","IMT Atlantique, Inserm UMR 1101, 29200 Brest, France"],"affiliations":[{"raw_affiliation_string":"CortAIx Labs, Thales, 91120 Palaiseau, France","institution_ids":["https://openalex.org/I4210140930"]},{"raw_affiliation_string":"IMT Atlantique, Inserm UMR 1101, 29200 Brest, France","institution_ids":["https://openalex.org/I4210127572","https://openalex.org/I154526488"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069264855","display_name":"Reda Bellafqira","orcid":"https://orcid.org/0000-0002-1131-4115"},"institutions":[{"id":"https://openalex.org/I154526488","display_name":"Inserm","ror":"https://ror.org/02vjkv261","country_code":"FR","type":"government","lineage":["https://openalex.org/I154526488"]},{"id":"https://openalex.org/I4210127572","display_name":"IMT Atlantique","ror":"https://ror.org/030hj3061","country_code":"FR","type":"education","lineage":["https://openalex.org/I205703379","https://openalex.org/I4210127572"]},{"id":"https://openalex.org/I4210161065","display_name":"Laboratoire de Traitement de l'Information M\u00e9dicale","ror":"https://ror.org/05mqemx33","country_code":"FR","type":"facility","lineage":["https://openalex.org/I154526488","https://openalex.org/I4210105774","https://openalex.org/I4210161065"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Reda Bellafqira","raw_affiliation_strings":["IMT Atlantique, Inserm UMR 1101, 29200 Brest, France","National Institute of Health and Medical Research (Inserm), UMR 1101 Latim, 29238 Brest, France"],"affiliations":[{"raw_affiliation_string":"IMT Atlantique, Inserm UMR 1101, 29200 Brest, France","institution_ids":["https://openalex.org/I4210127572","https://openalex.org/I154526488"]},{"raw_affiliation_string":"National Institute of Health and Medical Research (Inserm), UMR 1101 Latim, 29238 Brest, France","institution_ids":["https://openalex.org/I4210161065","https://openalex.org/I154526488"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062289182","display_name":"Gouenou Coatrieux","orcid":"https://orcid.org/0000-0002-5643-0224"},"institutions":[{"id":"https://openalex.org/I154526488","display_name":"Inserm","ror":"https://ror.org/02vjkv261","country_code":"FR","type":"government","lineage":["https://openalex.org/I154526488"]},{"id":"https://openalex.org/I4210127572","display_name":"IMT Atlantique","ror":"https://ror.org/030hj3061","country_code":"FR","type":"education","lineage":["https://openalex.org/I205703379","https://openalex.org/I4210127572"]},{"id":"https://openalex.org/I4210161065","display_name":"Laboratoire de Traitement de l'Information M\u00e9dicale","ror":"https://ror.org/05mqemx33","country_code":"FR","type":"facility","lineage":["https://openalex.org/I154526488","https://openalex.org/I4210105774","https://openalex.org/I4210161065"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Gouenou Coatrieux","raw_affiliation_strings":["IMT Atlantique, Inserm UMR 1101, 29200 Brest, France","National Institute of Health and Medical Research (Inserm), UMR 1101 Latim, 29238 Brest, France"],"affiliations":[{"raw_affiliation_string":"IMT Atlantique, Inserm UMR 1101, 29200 Brest, France","institution_ids":["https://openalex.org/I4210127572","https://openalex.org/I154526488"]},{"raw_affiliation_string":"National Institute of Health and Medical Research (Inserm), UMR 1101 Latim, 29238 Brest, France","institution_ids":["https://openalex.org/I4210161065","https://openalex.org/I154526488"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060291347","display_name":"Katarzyna Kapusta","orcid":"https://orcid.org/0000-0003-0963-4782"},"institutions":[{"id":"https://openalex.org/I4210140930","display_name":"Thales (France)","ror":"https://ror.org/04emwm605","country_code":"FR","type":"company","lineage":["https://openalex.org/I4210140930"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Katarzyna Kapusta","raw_affiliation_strings":["CortAIx Labs, Thales, 91120 Palaiseau, France"],"affiliations":[{"raw_affiliation_string":"CortAIx Labs, Thales, 91120 Palaiseau, France","institution_ids":["https://openalex.org/I4210140930"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5046279472","display_name":"Kassem Kallas","orcid":"https://orcid.org/0000-0001-7689-4125"},"institutions":[{"id":"https://openalex.org/I154526488","display_name":"Inserm","ror":"https://ror.org/02vjkv261","country_code":"FR","type":"government","lineage":["https://openalex.org/I154526488"]},{"id":"https://openalex.org/I4210161065","display_name":"Laboratoire de Traitement de l'Information M\u00e9dicale","ror":"https://ror.org/05mqemx33","country_code":"FR","type":"facility","lineage":["https://openalex.org/I154526488","https://openalex.org/I4210105774","https://openalex.org/I4210161065"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Kassem Kallas","raw_affiliation_strings":["National Institute of Health and Medical Research (Inserm), UMR 1101 Latim, 29238 Brest, France"],"affiliations":[{"raw_affiliation_string":"National Institute of Health and Medical Research (Inserm), UMR 1101 Latim, 29238 Brest, France","institution_ids":["https://openalex.org/I4210161065","https://openalex.org/I154526488"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5043935032"],"corresponding_institution_ids":["https://openalex.org/I154526488","https://openalex.org/I4210127572","https://openalex.org/I4210140930"],"apc_list":{"value":1400,"currency":"CHF","value_usd":1515},"apc_paid":{"value":1400,"currency":"CHF","value_usd":1515},"fwci":1.2181,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.77367689,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":"7","issue":"2","first_page":"32","last_page":"32"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9940000176429749,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.7246016263961792},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.686090350151062},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.6444801092147827},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5934371948242188},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5455779433250427},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5381091833114624},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.47172585129737854},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4220016598701477},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.34347397089004517}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.7246016263961792},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.686090350151062},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.6444801092147827},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5934371948242188},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5455779433250427},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5381091833114624},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.47172585129737854},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4220016598701477},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.34347397089004517}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.3390/make7020032","is_oa":true,"landing_page_url":"https://doi.org/10.3390/make7020032","pdf_url":"https://www.mdpi.com/2504-4990/7/2/32/pdf?version=1743500302","source":{"id":"https://openalex.org/S4210213891","display_name":"Machine Learning and Knowledge Extraction","issn_l":"2504-4990","issn":["2504-4990"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Machine Learning and Knowledge Extraction","raw_type":"journal-article"},{"id":"pmh:oai:HAL:hal-05110896v1","is_oa":true,"landing_page_url":"https://hal.science/hal-05110896","pdf_url":null,"source":{"id":"https://openalex.org/S4406922466","display_name":"SPIRE - Sciences Po Institutional REpository","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Machine Learning and Knowledge Extraction, 2025, 7, &#x27E8;10.3390/make7020032&#x27E9;","raw_type":"Journal articles"},{"id":"pmh:oai:doaj.org/article:cd883fa470ed42d08d01812daa93106a","is_oa":true,"landing_page_url":"https://doaj.org/article/cd883fa470ed42d08d01812daa93106a","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Machine Learning and Knowledge Extraction, Vol 7, Iss 2, p 32 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.3390/make7020032","is_oa":true,"landing_page_url":"https://doi.org/10.3390/make7020032","pdf_url":"https://www.mdpi.com/2504-4990/7/2/32/pdf?version=1743500302","source":{"id":"https://openalex.org/S4210213891","display_name":"Machine Learning and Knowledge Extraction","issn_l":"2504-4990","issn":["2504-4990"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Machine Learning and Knowledge Extraction","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2008681813","display_name":null,"funder_award_id":"ANR-22PESN-0006","funder_id":"https://openalex.org/F4320320883","funder_display_name":"Agence Nationale de la Recherche"},{"id":"https://openalex.org/G3477572256","display_name":null,"funder_award_id":"101070222","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"}],"funders":[{"id":"https://openalex.org/F4320320300","display_name":"European Commission","ror":"https://ror.org/00k4n6c32"},{"id":"https://openalex.org/F4320320883","display_name":"Agence Nationale de la Recherche","ror":"https://ror.org/00rbzpz17"}],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4409045452.pdf"},"referenced_works_count":31,"referenced_works":["https://openalex.org/W2108598243","https://openalex.org/W2112796928","https://openalex.org/W2117876524","https://openalex.org/W2194775991","https://openalex.org/W2579318729","https://openalex.org/W2768064608","https://openalex.org/W2786379237","https://openalex.org/W2806082141","https://openalex.org/W2899585792","https://openalex.org/W2935349488","https://openalex.org/W2970272159","https://openalex.org/W3036917029","https://openalex.org/W3118608800","https://openalex.org/W3135820585","https://openalex.org/W3156011647","https://openalex.org/W3206880386","https://openalex.org/W3216556018","https://openalex.org/W4220734809","https://openalex.org/W4307823382","https://openalex.org/W4311731280","https://openalex.org/W4319453091","https://openalex.org/W4320005719","https://openalex.org/W4375869159","https://openalex.org/W4387331442","https://openalex.org/W4390581920","https://openalex.org/W4390904846","https://openalex.org/W4391880762","https://openalex.org/W4393072702","https://openalex.org/W4400682512","https://openalex.org/W4402916165","https://openalex.org/W6677082149"],"related_works":["https://openalex.org/W2367449261","https://openalex.org/W2372007853","https://openalex.org/W2385289568","https://openalex.org/W4312601715","https://openalex.org/W4377865163","https://openalex.org/W4392828243","https://openalex.org/W4312822655","https://openalex.org/W3157170264","https://openalex.org/W4298185893","https://openalex.org/W4402427143"],"abstract_inverted_index":{"Due":[0],"to":[1,14,36,55,96,139,148,166],"their":[2,38],"considerable":[3],"costs,":[4],"deep":[5,109],"neural":[6,110],"networks":[7],"(DNNs)":[8],"are":[9],"valuable":[10],"assets":[11],"that":[12,42,90,154],"need":[13,54],"be":[15],"protected":[16],"in":[17,46,68,121],"terms":[18],"of":[19],"intellectual":[20],"property":[21],"(IP).":[22],"From":[23],"this":[24],"statement,":[25],"DNN":[26,34,123],"watermarking":[27,71,112,124],"gains":[28],"significant":[29],"interest":[30],"since":[31],"it":[32],"allows":[33],"owners":[35],"prove":[37],"ownership.":[39],"Various":[40],"methods":[41,93],"embed":[43],"ownership":[44],"information":[45],"the":[47,61,70,76,81,91],"model":[48],"behavior":[49],"have":[50],"been":[51],"proposed.":[52],"They":[53],"fill":[56],"several":[57],"requirements,":[58],"among":[59],"them":[60],"security,":[62,141],"which":[63,79,135,144],"represents":[64],"an":[65],"attacker\u2019s":[66],"difficulty":[67],"breaking":[69],"scheme.":[72],"There":[73],"is":[74,89],"also":[75],"robustness":[77,165],"requirement,":[78],"quantifies":[80],"resistance":[82],"against":[83],"watermark":[84],"removal":[85,167],"techniques.":[86],"The":[87],"problem":[88],"proposed":[92],"generally":[94],"fail":[95],"meet":[97],"these":[98],"necessary":[99],"standards.":[100],"This":[101],"paper":[102],"presents":[103],"RoSe-Mix,":[104],"a":[105,164],"robust":[106],"and":[107,142,161],"secure":[108],"network":[111],"technique":[113],"designed":[114],"for":[115],"black-box":[116],"settings.":[117],"It":[118],"addresses":[119],"limitations":[120],"existing":[122],"approaches":[125],"by":[126],"integrating":[127],"key":[128],"features":[129],"from":[130],"two":[131],"established":[132],"methods:":[133],"RoSe,":[134],"uses":[136],"cryptographic":[137],"hashing":[138],"ensure":[140],"Mixer,":[143],"employs":[145],"image":[146],"Mixup":[147],"enhance":[149],"robustness.":[150],"Experimental":[151],"results":[152],"demonstrate":[153],"RoSe-Mix":[155],"achieves":[156],"security":[157],"across":[158],"various":[159],"architectures":[160],"datasets":[162],"with":[163],"attacks":[168],"exceeding":[169],"99%.":[170]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-04-01T00:00:00"}
