仅用一张水印图就能去除隐形水印,且无需了解水印机制。
A Baseline Method for Removing Invisible Image Watermarks using Deep Image Prior
- 利用深度图像先验(DIP)从单张水印图中逐步重建出去水印图像。
- DIP中间迭代步骤可稳定生成高质量去水印结果,保留原始图像细节。
- 适用于评估水印系统鲁棒性,尤其对训练型可见水印效果有限。
图像水印被视作识别AI生成内容的有力手段,可用于版权保护或防止虚假图像滥用。本文提出一种黑盒方法,仅需单张水印图即可移除隐形水印,无需水印数据集或对水印系统的先验知识。方法基于深度图像先验(Deep Image Prior, DIP),通过回归水印图,在DIP的中间迭代过程中可靠地提取出可去除水印且保持高画质的逃逸图像。由于其独特工作机制与实际有效性,我们建议将DIP作为基准攻击方法用于水印系统鲁棒性评估。此外,通过分析DIP及其他现有黑盒方法在应对训练型可见水印时的局限性,本文讨论了训练型可见水印在遏制信息误导方面的潜在应用价值。
原文摘要 · Abstract (English)
Image watermarks have been considered a promising technique to help detect AI-generated content, which can be used to protect copyright or prevent fake image abuse. In this work, we present a black-box method for removing invisible image watermarks, without the need of any dataset of watermarked images or any knowledge about the watermark system. Our approach is simple to implement: given a single watermarked image, we regress it by deep image prior (DIP). We show that from the intermediate steps of DIP one can reliably find an evasion image that can remove invisible watermarks while preserving high image quality. Due to its unique working mechanism and practical effectiveness, we advocate including DIP as a baseline invasion method for benchmarking the robustness of watermarking systems. Finally, by showing the limited ability of DIP and other existing black-box methods in evading training-based visible watermarks, we discuss the positive implications on the practical use of training-based visible watermarks to prevent misinformation abuse.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。