arXiv:2505.21620cs.CRcs.AI2025-05被引 5

首个视频水印鲁棒性评测基准,揭示当前水印方法易被破解。

VideoMarkBench: Benchmarking Robustness of Video Watermarking

  • 构建统一数据集与多种攻击场景,系统评估水印鲁棒性。
  • 12类扰动下水印成功率普遍低于60%,暴露严重漏洞。
  • 适合研究生成视频安全、数字版权保护的学者和工程师。

视频生成模型的快速发展催生了大量高保真合成视频,引发虚假信息与版权侵权等伦理问题。近期提出在生成视频中嵌入不可见水印以实现后续检测,但现有水印方法对常规及对抗性扰动的鲁棒性仍缺乏系统评估。本文提出 VideoMarkBench,首个系统性基准,用于评估视频水印在水印移除与伪造攻击下的鲁棒性。研究基于三种顶尖视频生成模型,覆盖三种视频风格,集成四种水印方法与七种检测聚合策略。全面测试白盒、黑盒及无盒威胁模型下的12类扰动。结果表明,当前水印方法存在显著脆弱性,亟需更鲁棒的解决方案。代码已开源:https://github.com/zhengyuan-jiang/VideoMarkBench。

原文摘要 · Abstract (English)

The rapid development of video generative models has led to a surge in highly realistic synthetic videos, raising ethical concerns related to disinformation and copyright infringement. Recently, video watermarking has been proposed as a mitigation strategy by embedding invisible marks into AI-generated videos to enable subsequent detection. However, the robustness of existing video watermarking methods against both common and adversarial perturbations remains underexplored. In this work, we introduce VideoMarkBench, the first systematic benchmark designed to evaluate the robustness of video watermarks under watermark removal and watermark forgery attacks. Our study encompasses a unified dataset generated by three state-of-the-art video generative models, across three video styles, incorporating four watermarking methods and seven aggregation strategies used during detection. We comprehensively evaluate 12 types of perturbations under white-box, black-box, and no-box threat models. Our findings reveal significant vulnerabilities in current watermarking approaches and highlight the urgent need for more robust solutions. Our code is available at https://github.com/zhengyuan-jiang/VideoMarkBench.

视频水印鲁棒性评测生成视频安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。