[1]
Y. Xiao, “Class-feature Watermark: A Resilient Black-box Watermark Against Model Extraction Attacks”, AAAI, vol. 40, no. 42, pp. 35903–35912, Mar. 2026.