arXiv:2410.18775cs.CVcs.AI2024-10ICLR被引 134

提出新水印方法VINE,对抗图像编辑更鲁棒,兼顾画质与安全。

Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to Advances

  • 用频域分析发现模糊具相似特性,训练时模拟以增强抗干扰能力
  • 基于SDXL-Turbo模型实现低感知、高鲁棒水印嵌入,显著提升存活率
  • 首个全面评测水印鲁棒性的基准W-Bench,覆盖多种主流图像编辑

当前图像水印方法易受大规模文本到图像模型驱动的先进编辑技术影响,这些技术在编辑过程中会破坏嵌入水印,严重威胁版权保护。本文提出W-Bench,首个系统性评估水印方法对多种图像编辑技术(包括图像重生成、全局编辑、局部编辑及图像转视频)鲁棒性的基准。通过评估11种代表性水印方法,发现多数方法在编辑后无法检测水印。为解决此问题,提出VINE水印方法,在保持高图像质量的同时显著提升对各类编辑的鲁棒性。核心创新:(1) 分析图像编辑的频率特征,发现模糊失真具有相似频域特性,可作为训练中的代理攻击以强化鲁棒性;(2) 采用大规模预训练扩散模型SDXL-Turbo,适配水印任务,实现更隐蔽且坚固的嵌入。实验表明,VINE在多种编辑场景下均优于现有方法,在图像质量和鲁棒性上表现优异。代码已开源:https://github.com/Shilin-LU/VINE。

原文摘要 · Abstract (English)

Current image watermarking methods are vulnerable to advanced image editing techniques enabled by large-scale text-to-image models. These models can distort embedded watermarks during editing, posing significant challenges to copyright protection. In this work, we introduce W-Bench, the first comprehensive benchmark designed to evaluate the robustness of watermarking methods against a wide range of image editing techniques, including image regeneration, global editing, local editing, and image-to-video generation. Through extensive evaluations of eleven representative watermarking methods against prevalent editing techniques, we demonstrate that most methods fail to detect watermarks after such edits. To address this limitation, we propose VINE, a watermarking method that significantly enhances robustness against various image editing techniques while maintaining high image quality. Our approach involves two key innovations: (1) we analyze the frequency characteristics of image editing and identify that blurring distortions exhibit similar frequency properties, which allows us to use them as surrogate attacks during training to bolster watermark robustness; (2) we leverage a large-scale pretrained diffusion model SDXL-Turbo, adapting it for the watermarking task to achieve more imperceptible and robust watermark embedding. Experimental results show that our method achieves outstanding watermarking performance under various image editing techniques, outperforming existing methods in both image quality and robustness. Code is available at https://github.com/Shilin-LU/VINE.

图像水印扩散模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。