Y. Uchida, Y. Nagai, S. Sakazawa, and S. Satoh, “Embedding watermarks into deep neural networks,” in Proc. ACM ICMR, 2017, pp. 269–277.H. Poursiami, I. Alouani, and M. Parsa, “Watermarking neuromorphic brains: Intellectual property protection in spiking neural networks,” in Proc. ICONS, 2024, pp. 287–294.G. Ren, G. Li, S. Li, L. Chen, and K. Ren, “ActiveDaemon: Unconscious DNN dormancy and waking up via user-specific invisible token,” in Proc. NDSS, 2024.W. Fang, Y. Chen, J. Ding, Z. Yu, T. Masquelier, D. Chen, L. Huang, H. Zhou, G. Li, and Y. Tian, “Spikingjelly: An open-source machine learning infrastructure platform for spike-based intelligence,” Sci. Adv., vol. 9, no. 40, p. eadi1480, 2023.B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in Proc. IEEE SP, 2019, pp. 707–723.G. Ren, J. Wu, G. Li, S. Li, and M. Guizani, “Protecting intellectual property with reliable availability of learning models in ai-based cybersecurity services,” IEEE TDSC, vol. 21, no. 2, pp. 600–617, 2022.J. Xia, Z. Yue, Y. Zhou, Z. Ling, Y. Shi, X. Wei, and M. Chen, “WaveAttack: Asymmetric frequency obfuscation-based backdoor attacks against deep neural networks,” in Proc. NeurIPS. Curran Associates, Inc., 2024, pp. 43 549–43 570.