arXiv:2410.15075cs.CVcs.AI2024-10中稿 · ACM Multimedia Asi…被引 5

用压缩域水印让篡改图像自动变糊,保护数字图片真实性的新编码方法

SLIC: Secure Learned Image Codec through Compressed Domain Watermarking to Defend Image Manipulation

  • 在神经网络压缩的隐空间嵌入对抗性水印,实现主动防篡改
  • 篡改后重新压缩会引发明显画质劣化,有效阻止非法传播
  • 兼顾水印隐蔽性和鲁棒性,适合社交平台图像安全防护

数字图像篡改和生成式AI(如Deepfake)的发展,使社交媒体上图片的真实性受到严重威胁。传统图像取证技术多为被动应对,难以抵御复杂篡改手段。本文提出安全学习图像编解码器SLIC,通过在压缩域嵌入水印实现主动验证。SLIC利用基于神经网络的压缩,在隐空间中嵌入对抗性扰动作为水印,使得篡改后的图像在再次压缩时出现显著画质下降,从而形成防御机制。该方法通过微调神经编码器/解码器,在保证非水印图像质量损失极小的前提下,平衡水印的隐蔽性与鲁棒性。实验表明,该方法能有效在篡改图像中生成可见伪影,阻止其传播。本工作为可广泛部署的安全图像编解码器提供了重要进展。

原文摘要 · Abstract (English)

The digital image manipulation and advancements in Generative AI, such as Deepfake, has raised significant concerns regarding the authenticity of images shared on social media. Traditional image forensic techniques, while helpful, are often passive and insufficient against sophisticated tampering methods. This paper introduces the Secure Learned Image Codec (SLIC), a novel active approach to ensuring image authenticity through watermark embedding in the compressed domain. SLIC leverages neural network-based compression to embed watermarks as adversarial perturbations in the latent space, creating images that degrade in quality upon re-compression if tampered with. This degradation acts as a defense mechanism against unauthorized modifications. Our method involves fine-tuning a neural encoder/decoder to balance watermark invisibility with robustness, ensuring minimal quality loss for non-watermarked images. Experimental results demonstrate SLIC's effectiveness in generating visible artifacts in tampered images, thereby preventing their redistribution. This work represents a significant step toward developing secure image codecs that can be widely adopted to safeguard digital image integrity.

图像安全水印技术生成对抗

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。