arXiv:2412.10049cs.CV2024-12被引 5

无需训练即可实现高保真强鲁棒的图像水印,利用超分模型增强抗攻击能力。

SuperMark: Robust and Training-free Image Watermarking via Diffusion-based Super-Resolution

  • 用水印嵌入噪声,通过预训练超分模型生成水印图,逆过程提取水印。
  • 标准畸变下提取准确率达99.46%,自适应攻击下仍保持89.29%准确率。
  • 无需训练、可跨数据集/模型/分辨率使用,适合实际版权保护场景。

在人工智能生成内容与真实内容融合的当下,版权保护与内容认证需求日益迫切。水印技术成为关键手段,需抵御各类失真与攻击。现有深度水印方法多采用编码-加噪-解码架构,虽经大量训练,仍难以兼顾鲁棒性与保真度,且易受自适应攻击。为此,我们提出SuperMark——一种无需训练的鲁棒水印框架。受扩散模型去噪/加噪过程启发,SuperMark将水印嵌入初始高斯噪声,并通过预训练超分辨率(SR)模型去噪生成最终水印图像;提取时则通过DDIM反演将水印图还原为初始水印噪声,从而提取水印。该框架兼容多种噪声注入方式与扩散式超分模型,支持灵活定制。实验表明,SuperMark在保真度相当的前提下显著提升鲁棒性:标准畸变下平均提取准确率达99.46%,自适应攻击下仍达89.29%。同时具备优异跨数据集、模型、嵌入方法与分辨率的迁移能力。

原文摘要 · Abstract (English)

In today's digital landscape, the blending of AI-generated and authentic content has underscored the need for copyright protection and content authentication. Watermarking has become a vital tool to address these challenges, safeguarding both generated and real content. Effective watermarking methods must withstand various distortions and attacks. Current deep watermarking techniques often use an encoder-noise layer-decoder architecture and include distortions to enhance robustness. However, they struggle to balance robustness and fidelity and remain vulnerable to adaptive attacks, despite extensive training. To overcome these limitations, we propose SuperMark, a robust, training-free watermarking framework. Inspired by the parallels between watermark embedding/extraction in watermarking and the denoising/noising processes in diffusion models, SuperMark embeds the watermark into initial Gaussian noise using existing techniques. It then applies pre-trained Super-Resolution (SR) models to denoise the watermarked noise, producing the final watermarked image. For extraction, the process is reversed: the watermarked image is inverted back to the initial watermarked noise via DDIM Inversion, from which the embedded watermark is extracted. This flexible framework supports various noise injection methods and diffusion-based SR models, enabling enhanced customization. The robustness of the DDIM Inversion process against perturbations allows SuperMark to achieve strong resilience to distortions while maintaining high fidelity. Experiments demonstrate that SuperMark achieves fidelity comparable to existing methods while significantly improving robustness. Under standard distortions, it achieves an average watermark extraction accuracy of 99.46%, and 89.29% under adaptive attacks. Moreover, SuperMark shows strong transferability across datasets, SR models, embedding methods, and resolutions.

图像水印扩散模型超分辨率鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。