arXiv:2505.01474cs.CRcs.AI2025-05被引 2

提出新攻击方法,可彻底移除图像水印且画质损失极小。

Watermark Overwriting Attack on StegaStamp algorithm

  • 设计针对性算法,精准覆盖原水印信号
  • 在图像质量损失低于0.5%情况下实现水印清除
  • 适用于对抗隐形水印系统,尤其适合安全研究者

本文针对 StegaStamp 水印算法提出一种攻击方法,可在图像质量损失低于0.5%的条件下完全移除水印,该方法是为 NeurIPS「Erasing the invisible」竞赛开发。攻击通过生成特定扰动覆盖原始水印嵌入信号,使接收端无法检测到水印存在。实验表明,该方法在多种测试图像上均能实现高成功率的水印擦除,同时保持视觉感知质量接近原始图像。该工作揭示了现有隐写算法在对抗性攻击下的脆弱性,为水印系统的安全性评估提供了新视角。

原文摘要 · Abstract (English)

This paper presents an attack method on the StegaStamp watermarking algorithm that completely removes watermarks from an image with minimal quality loss, developed as part of the NeurIPS "Erasing the invisible" competition.

水印攻击隐写术对抗样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。