通过优化图像隐空间频域实现隐蔽水印,抗再生攻击能力强。
FreqMark: Invisible Image Watermarking via Frequency Based Optimization in Latent Space
- 在VAE编码的隐空间中直接优化频域特征嵌入水印。
- 48比特水印在多种攻击下准确率超90%,图像质量保持良好。
- 适合需要高鲁棒性与隐蔽性的数字版权保护场景。
不可见水印对数字内容的版权保护和内容认证至关重要。然而,现有方法在面对再生攻击时鲁棒性不足。本文提出一种新方法FreqMark,通过无约束优化经VAE编码后的图像隐空间频域实现水印嵌入,并利用预训练图像编码器提取水印。该优化策略可在图像质量与水印鲁棒性间灵活权衡,有效抵御再生攻击。实验表明,FreqMark在图像质量与鲁棒性方面均有显著优势,支持灵活选择编码比特数,在多种攻击场景下对48比特隐藏信息的比特准确率超过90%。
原文摘要 · Abstract (English)
Invisible watermarking is essential for safeguarding digital content, enabling copyright protection and content authentication. However, existing watermarking methods fall short in robustness against regeneration attacks. In this paper, we propose a novel method called FreqMark that involves unconstrained optimization of the image latent frequency space obtained after VAE encoding. Specifically, FreqMark embeds the watermark by optimizing the latent frequency space of the images and then extracts the watermark through a pre-trained image encoder. This optimization allows a flexible trade-off between image quality with watermark robustness and effectively resists regeneration attacks. Experimental results demonstrate that FreqMark offers significant advantages in image quality and robustness, permits flexible selection of the encoding bit number, and achieves a bit accuracy exceeding 90% when encoding a 48-bit hidden message under various attack scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。