Xiao, Yaxin, Qingqing Ye, Zi Liang, Haoyang Li, RongHua Li, Huadi Zheng, and Haibo Hu. “Class-Feature Watermark: A Resilient Black-Box Watermark Against Model Extraction Attacks”. Proceedings of the AAAI Conference on Artificial Intelligence 40, no. 42 (March 14, 2026): 35903–35912. Accessed May 14, 2026. https://ojs.aaai.org/index.php/AAAI/article/view/40905.