arXiv:2412.07129cs.CV2024-12被引 1

为艺术风格图像设计抗黑盒风格迁移的鲁棒水印方法

StyleMark: A Robust Watermarking Method for Art Style Images Against Black-Box Arbitrary Style Transfer

  • 通过多尺度嵌入调整风格特征均值,将水印植入共享风格空间
  • 在黑盒风格迁移下仍保持水印可检测性,对抗攻击成功率低于5%
  • 适合保护数字艺术版权,尤其适用于未经授权的风格迁移场景

任意风格迁移(AST)可将自然图像转换为任意艺术风格图像,促进艺术传播。然而,未经许可使用艺术风格图像进行AST可能侵犯艺术家版权。一种应对措施是鲁棒水印,通过在载体中嵌入版权水印来追踪图像传播。然而,AST生成的图像会丢失原风格图像的结构和语义信息,导致水印难以实现端到端追踪。为此,我们提出StyleMark,首个针对黑盒AST的鲁棒水印方法,可无缝应用于艺术风格图像,在经AST后仍能精确追溯艺术风格来源。具体而言,我们设计了一种新型风格水印网络,通过多尺度水印嵌入调节风格特征的均值,将水印痕迹植入风格图像的共享特征空间。同时,提出分布压缩损失,限制内容统计特征失真,迫使重建网络聚焦于融合带水印的风格特征,从而优化内在水印分布。最后,基于端到端训练,通过在随机噪声下的解码器微调,缓解鲁棒性与水印不可见性之间的优化冲突。实验结果表明,StyleMark在黑盒风格迁移和常见像素级失真下表现出显著鲁棒性,且能有效防御恶意自适应攻击。

原文摘要 · Abstract (English)

Arbitrary Style Transfer (AST) achieves the rendering of real natural images into the painting styles of arbitrary art style images, promoting art communication. However, misuse of unauthorized art style images for AST may infringe on artists' copyrights. One countermeasure is robust watermarking, which tracks image propagation by embedding copyright watermarks into carriers. Unfortunately, AST-generated images lose the structural and semantic information of the original style image, hindering end-to-end robust tracking by watermarks. To fill this gap, we propose StyleMark, the first robust watermarking method for black-box AST, which can be seamlessly applied to art style images achieving precise attribution of artistic styles after AST. Specifically, we propose a new style watermark network that adjusts the mean activations of style features through multi-scale watermark embedding, thereby planting watermark traces into the shared style feature space of style images. Furthermore, we design a distribution squeeze loss, which constrain content statistical feature distortion, forcing the reconstruction network to focus on integrating style features with watermarks, thus optimizing the intrinsic watermark distribution. Finally, based on solid end-to-end training, StyleMark mitigates the optimization conflict between robustness and watermark invisibility through decoder fine-tuning under random noise. Experimental results demonstrate that StyleMark exhibits significant robustness against black-box AST and common pixel-level distortions, while also securely defending against malicious adaptive attacks.

风格迁移水印技术版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。