arXiv:2502.20924cs.CV2025-02CVPR被引 6

为免版权水印被梯度攻击移除,提出可证明的防护机制。

Decoder Gradient Shield: Provable and High-Fidelity Prevention of Gradient-Based Box-Free Watermark Removal

  • 在解码器中加入梯度屏蔽层,用闭式解防止梯度攻击
  • 使水印移除器训练损失无法收敛至无防护水平
  • 保护水印同时保持图像质量,适合模型版权保护场景

深度图像到图像模型的知识产权可通过无框水印技术保护,该技术利用编码器嵌入、解码器提取不可见版权标记。现有工作主要优化编码器设计以提升水印鲁棒性,但忽略了与编码器联合训练的解码器存在被攻击漏洞——可被用于训练水印移除网络。为此,本文提出解码器梯度屏蔽(DGS),作为解码器API中的防护层,通过闭式解法阻止基于梯度的水印移除。其核心思想受经典对抗攻击启发,首次用于无框水印的防御。实验表明,DGS能重新定向并重缩放水印查询的梯度方向,使水印移除器的训练损失无法达到无防护时的收敛水平,同时保持解码器输出图像质量。代码将在论文接收后公开。

原文摘要 · Abstract (English)

The intellectual property of deep image-to-image models can be protected by the so-called box-free watermarking. It uses an encoder and a decoder, respectively, to embed into and extract from the model's output images invisible copyright marks. Prior works have improved watermark robustness, focusing on the design of better watermark encoders. In this paper, we reveal an overlooked vulnerability of the unprotected watermark decoder which is jointly trained with the encoder and can be exploited to train a watermark removal network. To defend against such an attack, we propose the decoder gradient shield (DGS) as a protection layer in the decoder API to prevent gradient-based watermark removal with a closed-form solution. The fundamental idea is inspired by the classical adversarial attack, but is utilized for the first time as a defensive mechanism in the box-free model watermarking. We then demonstrate that DGS can reorient and rescale the gradient directions of watermarked queries and stop the watermark remover's training loss from converging to the level without DGS, while retaining decoder output image quality. Experimental results verify the effectiveness of proposed method. Code of paper will be made available upon acceptance.

水印防护梯度攻击模型版权

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。