{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2022:VAM2VKFTAE72RQAWQ2YIA57I6T","short_pith_number":"pith:VAM2VKFT","schema_version":"1.0","canonical_sha256":"a819aaa8b3013fa8c01686b08077e8f4e9d101b033092117735320555482540a","source":{"kind":"arxiv","id":"2209.03563","version":2},"attestation_state":"computed","paper":{"title":"SSL-WM: A Black-Box Watermarking Approach for Encoders Pre-trained by Self-supervised Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chang Yue, Fan Xiang, Guozhu Meng, Hualong Ma, Kai Chen, Pan Li, Peizhuo Lv, Ruigang Liang, Shenchen Zhu, Shengzhi Zhang, Yingjun Zhang, Yuling Cai","submitted_at":"2022-09-08T05:02:11Z","abstract_excerpt":"Recent years have witnessed tremendous success in Self-Supervised Learning (SSL), which has been widely utilized to facilitate various downstream tasks in Computer Vision (CV) and Natural Language Processing (NLP) domains. However, attackers may steal such SSL models and commercialize them for profit, making it crucial to verify the ownership of the SSL models. Most existing ownership protection solutions (e.g., backdoor-based watermarks) are designed for supervised learning models and cannot be used directly since they require that the models' downstream tasks and target labels be known and a"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2209.03563","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-09-08T05:02:11Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"6e85d52e4f1f315fc3990dcf05b18bfedb9ddce79f4326696eff84ab420f0dc9","abstract_canon_sha256":"40ab4f149bde578c65cd4fae216a025ffede063390d62f061161d8331328f050"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:38:24.825019Z","signature_b64":"hlAF+Moqjjrr1brP0Q1+nMaXoLwoOaL6Y7IQbWvE9+Pk0QuwTM+nB5LOOzhP39VLoCPlKFfXVE+b36SnJixWDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a819aaa8b3013fa8c01686b08077e8f4e9d101b033092117735320555482540a","last_reissued_at":"2026-07-05T07:38:24.824514Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:38:24.824514Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SSL-WM: A Black-Box Watermarking Approach for Encoders Pre-trained by Self-supervised Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chang Yue, Fan Xiang, Guozhu Meng, Hualong Ma, Kai Chen, Pan Li, Peizhuo Lv, Ruigang Liang, Shenchen Zhu, Shengzhi Zhang, Yingjun Zhang, Yuling Cai","submitted_at":"2022-09-08T05:02:11Z","abstract_excerpt":"Recent years have witnessed tremendous success in Self-Supervised Learning (SSL), which has been widely utilized to facilitate various downstream tasks in Computer Vision (CV) and Natural Language Processing (NLP) domains. However, attackers may steal such SSL models and commercialize them for profit, making it crucial to verify the ownership of the SSL models. Most existing ownership protection solutions (e.g., backdoor-based watermarks) are designed for supervised learning models and cannot be used directly since they require that the models' downstream tasks and target labels be known and a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2209.03563","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2209.03563/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2209.03563","created_at":"2026-07-05T07:38:24.824575+00:00"},{"alias_kind":"arxiv_version","alias_value":"2209.03563v2","created_at":"2026-07-05T07:38:24.824575+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2209.03563","created_at":"2026-07-05T07:38:24.824575+00:00"},{"alias_kind":"pith_short_12","alias_value":"VAM2VKFTAE72","created_at":"2026-07-05T07:38:24.824575+00:00"},{"alias_kind":"pith_short_16","alias_value":"VAM2VKFTAE72RQAW","created_at":"2026-07-05T07:38:24.824575+00:00"},{"alias_kind":"pith_short_8","alias_value":"VAM2VKFT","created_at":"2026-07-05T07:38:24.824575+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2512.15641","citing_title":"ComMark: Covert and Robust Black-Box Model Watermarking with Compressed Samples","ref_index":40,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T","json":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T.json","graph_json":"https://pith.science/api/pith-number/VAM2VKFTAE72RQAWQ2YIA57I6T/graph.json","events_json":"https://pith.science/api/pith-number/VAM2VKFTAE72RQAWQ2YIA57I6T/events.json","paper":"https://pith.science/paper/VAM2VKFT"},"agent_actions":{"view_html":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T","download_json":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T.json","view_paper":"https://pith.science/paper/VAM2VKFT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2209.03563&json=true","fetch_graph":"https://pith.science/api/pith-number/VAM2VKFTAE72RQAWQ2YIA57I6T/graph.json","fetch_events":"https://pith.science/api/pith-number/VAM2VKFTAE72RQAWQ2YIA57I6T/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T/action/storage_attestation","attest_author":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T/action/author_attestation","sign_citation":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T/action/citation_signature","submit_replication":"https://pith.science/pith/VAM2VKFTAE72RQAWQ2YIA57I6T/action/replication_record"}},"created_at":"2026-07-05T07:38:24.824575+00:00","updated_at":"2026-07-05T07:38:24.824575+00:00"}