arXiv:2502.04901cs.CRcs.LG2025-02被引 10

提出可公开检测的鲁棒水印理论框架,指出当前技术难以实现。

On the Difficulty of Constructing a Robust and Publicly-Detectable Watermark

  • 构建了兼具鲁棒性、不可伪造和公开可检的水印理论模型
  • 证明该水印方案理论上存在,但现有深度学习能力不足
  • 为未来可信数字内容溯源研究指明关键方向

本文研究了可公开检测水印方案的理论边界,旨在实现图像来源追溯。基于元数据的方法(如C2PA)具备不可伪造性和公开可检测性,而机器学习技术则提供鲁棒的检索与水印能力。然而,目前尚无方案能同时满足鲁棒性、不可伪造性和公开可检测性。本文首次形式化定义此类方案并证明其存在性。尽管理论上可行,但现阶段缺乏足够深度学习能力来实现其中关键组件。文章分析了这些技术瓶颈,并提出了亟待解决的研究方向,以推动可信赖数字内容溯源的实际落地。

原文摘要 · Abstract (English)

This work investigates the theoretical boundaries of creating publicly-detectable schemes to enable the provenance of watermarked imagery. Metadata-based approaches like C2PA provide unforgeability and public-detectability. ML techniques offer robust retrieval and watermarking. However, no existing scheme combines robustness, unforgeability, and public-detectability. In this work, we formally define such a scheme and establish its existence. Although theoretically possible, we find that at present, it is intractable to build certain components of our scheme without a leap in deep learning capabilities. We analyze these limitations and propose research directions that need to be addressed before we can practically realize robust and publicly-verifiable provenance.

水印可信溯源深度学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。