1.
Xiao Y, Ye Q, Liang Z, Li H, Li R, Zheng H, et al. Class-feature Watermark: A Resilient Black-box Watermark Against Model Extraction Attacks. AAAI [Internet]. 2026 Mar. 14 [cited 2026 May 14];40(42):35903-12. Available from: https://ojs.aaai.org/index.php/AAAI/article/view/40905