{"id":"https://openalex.org/W7156839682","doi":"https://doi.org/10.48550/arxiv.2604.23568","title":"Green-Red Watermarking for Recommender Systems","display_name":"Green-Red Watermarking for Recommender Systems","publication_year":2026,"publication_date":"2026-04-26","ids":{"openalex":"https://openalex.org/W7156839682","doi":"https://doi.org/10.48550/arxiv.2604.23568"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.23568","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23568","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.23568","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5134776385","display_name":"Lei Zhou","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhou, Lei","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134814688","display_name":"Min Gao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gao, Min","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134753327","display_name":"Zongwei Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Zongwei","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100779889","display_name":"Yu Bai","orcid":"https://orcid.org/0000-0003-1087-5751"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bai, Yibing","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5134786565","display_name":"Wentao Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Wentao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.21780000627040863,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.21780000627040863,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.10109999775886536,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.07010000199079514,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.7628999948501587},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6126999855041504},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5491999983787537},{"id":"https://openalex.org/keywords/recommender-system","display_name":"Recommender system","score":0.4514000117778778},{"id":"https://openalex.org/keywords/probabilistic-logic","display_name":"Probabilistic logic","score":0.4153999984264374},{"id":"https://openalex.org/keywords/statistical-model","display_name":"Statistical model","score":0.4101000130176544},{"id":"https://openalex.org/keywords/ranking","display_name":"Ranking (information retrieval)","score":0.3912000060081482}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7897999882698059},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.7628999948501587},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6126999855041504},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5491999983787537},{"id":"https://openalex.org/C557471498","wikidata":"https://www.wikidata.org/wiki/Q554950","display_name":"Recommender system","level":2,"score":0.4514000117778778},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4415999948978424},{"id":"https://openalex.org/C49937458","wikidata":"https://www.wikidata.org/wiki/Q2599292","display_name":"Probabilistic logic","level":2,"score":0.4153999984264374},{"id":"https://openalex.org/C114289077","wikidata":"https://www.wikidata.org/wiki/Q3284399","display_name":"Statistical model","level":2,"score":0.4101000130176544},{"id":"https://openalex.org/C189430467","wikidata":"https://www.wikidata.org/wiki/Q7293293","display_name":"Ranking (information retrieval)","level":2,"score":0.3912000060081482},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.38659998774528503},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3666999936103821},{"id":"https://openalex.org/C30038468","wikidata":"https://www.wikidata.org/wiki/Q4354775","display_name":"Memorization","level":2,"score":0.3506999909877777},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.34439998865127563},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.3142000138759613},{"id":"https://openalex.org/C87007009","wikidata":"https://www.wikidata.org/wiki/Q210832","display_name":"Statistical hypothesis testing","level":2,"score":0.30869999527931213},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3052999973297119},{"id":"https://openalex.org/C52146309","wikidata":"https://www.wikidata.org/wiki/Q7431116","display_name":"Schema (genetic algorithms)","level":2,"score":0.3012000024318695},{"id":"https://openalex.org/C42812","wikidata":"https://www.wikidata.org/wiki/Q1082910","display_name":"Partition (number theory)","level":2,"score":0.29159998893737793},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.28780001401901245},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.2721000015735626},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.2671000063419342}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.23568","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23568","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.23568","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23568","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.6153385639190674}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"widespread":[1],"open-sourcing":[2],"of":[3,11,21,196],"advanced":[4],"recommendation":[5],"algorithms":[6],"and":[7,55,102,166,212],"the":[8,18,93,109,126,140,158,193,197],"rising":[9],"threat":[10],"model":[12,177],"extraction":[13,215],"attacks":[14,60,216],"have":[15],"made":[16],"safeguarding":[17],"intellectual":[19],"property":[20],"recommender":[22,84],"systems":[23],"an":[24],"imperative":[25],"task.":[26],"While":[27],"watermarking":[28],"serves":[29],"as":[30,105],"a":[31,78,88,115],"potent":[32],"defense,":[33],"existing":[34,219],"methods":[35],"primarily":[36],"rely":[37],"on":[38,176,187,201],"forcing":[39],"models":[40,204],"to":[41,58,62,91,114,143,157,162,218],"memorize":[42],"pre-defined":[43],"interaction":[44],"patterns.":[45],"Such":[46],"memorization-based":[47],"approaches":[48],"often":[49],"require":[50],"excessive":[51],"synthetic":[52],"data":[53,224],"injection":[54,156,173],"are":[56],"vulnerable":[57],"removal":[59],"due":[61],"their":[63],"detectable":[64],"statistical":[65,184],"deviations":[66],"from":[67,111],"natural":[68],"user":[69],"behavior.":[70],"To":[71],"address":[72],"these":[73],"limitations,":[74],"we":[75],"propose":[76],"GREW,":[77],"novel":[79],"Green-REd":[80],"Watermarking":[81],"framework":[82],"for":[83,99,147],"systems.":[85],"GREW":[86,130,207],"leverages":[87],"secret":[89,141],"key":[90,142],"partition":[92],"item":[94,160,198],"space":[95],"into":[96,125],"\"green\"":[97],"items":[98,104,146],"soft":[100],"promotion":[101],"\"red\"":[103],"anchors,":[106],"thereby":[107],"shifting":[108],"paradigm":[110],"fragile":[112],"memorization":[113],"stealthy,":[116],"key-controlled":[117],"output":[118],"bias.":[119],"By":[120],"integrating":[121],"watermark":[122],"signals":[123],"directly":[124],"intrinsic":[127],"ranking":[128,164],"process,":[129],"employs":[131],"three":[132],"recommendation-tailored":[133],"modules:":[134],"(1)":[135],"Semantic-Consistent":[136],"Hashing,":[137],"which":[138,153,170],"utilizes":[139],"cluster":[144],"green":[145],"performance-aware":[148],"stealthiness;":[149],"(2)":[150],"Decision-Aligned":[151],"Masking,":[152],"confines":[154],"signal":[155],"competitive":[159],"subset":[161],"preserve":[163],"logic;":[165],"(3)":[167],"Confidence-Aware":[168],"Scaling,":[169],"dynamically":[171],"modulates":[172],"intensity":[174],"based":[175],"uncertainty.":[178],"Ownership":[179],"verification":[180,211],"is":[181,228],"performed":[182],"via":[183],"hypothesis":[185],"testing":[186],"aggregated":[188],"black-box":[189],"outputs,":[190],"enabled":[191],"by":[192],"keyed":[194],"re-partitioning":[195],"space.":[199],"Experiments":[200],"multiple":[202],"base":[203],"demonstrate":[205],"that":[206],"achieves":[208],"strong":[209],"ownership":[210],"robustness":[213],"against":[214],"compared":[217],"baselines":[220],"while":[221],"requiring":[222],"no":[223],"injection.":[225],"Our":[226],"code":[227],"available":[229],"at":[230],"https://github.com/Loche2/GREW.":[231]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-04-29T00:00:00"}
