Abstract: Highlights•The proposed scheme is the first SDM watermarking that can resist ambiguity attacks.•The implementation of the scheme only requires a small cost.•Our method does not need the original training data.•The proposed method does not significantly degrade the performance of SDMs.
Loading