{"id":"W4288057808","doi":"10.1109/sp46214.2022.9833693","title":"SoK: How Robust is Image Classification Deep Neural Network Watermarking?","year":2022,"lang":"en","type":"article","venue":"2022 IEEE Symposium on Security and Privacy (SP)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":66,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Digital watermarking; Robustness (evolution); Watermark; Computer science; Artificial intelligence; Artificial neural network; Data mining; Deep neural networks; Set (abstract data type); Pattern recognition (psychology); Image (mathematics); Machine learning","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.004820378,0.001227333,0.0009587575,0.001127296,0.000720553,0.002100991,0.001708048,0.002554999,0.002383341],"category_scores_gemma":[0.02855032,0.0003586971,0.0008223315,0.0006892249,0.002464201,0.006445234,0.00224716,0.002452887,0.0009976579],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001293155,"about_ca_system_score_gemma":0.0009451323,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001258708,"about_ca_topic_score_gemma":0.001436923,"domain_scores_codex":[0.9967346,0.000774594,0.000254517,0.0006674585,0.001269982,0.0002989358],"domain_scores_gemma":[0.9929225,0.002529463,0.0007909057,0.00296881,0.0006354881,0.0001527849],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.001509152,0.0002430476,0.006515887,0.0007678871,0.0005839852,0.0003407334,0.0002824642,0.3288765,0.0526871,0.05206924,0.01118909,0.5449349],"study_design_scores_gemma":[0.00007015379,0.0003689936,0.001594576,0.0001776158,0.0001213713,0.000362468,0.0001398662,0.8863013,0.05377293,0.05077907,0.006237216,0.00007438775],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.281233,0.008348229,0.6696851,0.007500716,0.001197242,0.000315226,0.001098905,0.01013208,0.02048958],"genre_scores_gemma":[0.9059991,0.0013849,0.08654941,0.0007491611,0.0001827353,0.0001099496,0.0007339568,0.0004997769,0.003791061],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.004820378,"threshold_uncertainty_score":0.02549291,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.0187109019954699,"score_gpt":0.2471393926217866,"score_spread":0.2284284906263167,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}