Jing Xiao, Song Xiao, Chao Guo, Chuce He, Yahui Ding · Journal of King Saud University - Computer and Information Sciences 2026 · 2026
DOI: 10.1007/s44443-026-01195-3
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Model watermarking is a commonly used ownership verification technique for protecting the copyright of deep learning models. However, in practically deployed black-box model service scenarios, existing methods typically rely on misclassification-based backdoor trigger mechanisms, or assume that the verifier can obtain richer model output information such as soft labels and confidence scores. As a result, they struggle to simultaneously satisfy the requirements of unforgeability, harmlessness, and stealthiness in strict hard-label black-box settings. To address this issue, we propose a backdoor-free model watermarking method based on differential verification of adversarial samples and multi-bit information extraction. The proposed method embeds multi-bit information into the perturbations of targeted adversarial examples and constructs two watermark query sets for black-box verification from these information-bearing adversarial examples. By comparing the difference in correct classification responses of the model under verification on the two watermark query sets, the existence of the model watermark can be determined. Meanwhile, multi-bit information is further extracted from the adversarial perturbations of the query samples to verify whether the samples were generated by the legitimate model owner, thereby providing verifiable evidence of query sample legitimacy for third-party authorities in copyright dispute scenarios. Without introducing any misclassification backdoor, the proposed method provides dual protection through watermark existence verification and query sample legitimacy verification. Extensive experimental results demonstrate that the proposed method can achieve stable and reliable ownership verification while preserving the performance of the main task, and can effectively satisfy the requirements of unforgeability, harmlessness, and stealthiness.
No comments yet — start the discussion below.