首个针对3DGS水印的通用黑盒攻击框架,可高效移除水印且保持画面质量。
Fading the Digital Ink: A Universal Black-Box Attack Framework for 3DGS Watermarking Systems
- 将攻击建模为多目标优化问题,平衡水印清除与视觉保真度。
- 在黑盒环境下通过最小化特征方差使检测器失效,实现隐蔽攻击。
- 适用于主流3DGS水印系统,揭示现有版权保护方案的严重漏洞。
随着3D高斯点云(3DGS)的兴起,多种数字水印技术被用于版权保护,包括嵌入1维比特流或2维图像。然而,这些水印技术对潜在攻击的鲁棒性尚未得到充分研究。本文提出首个通用黑盒攻击框架——基于群体的多目标进化攻击(GMEA),旨在挑战现有水印系统。我们将攻击建模为大规模多目标优化问题,权衡水印消除与视觉质量。在黑盒设置下,引入间接目标函数,通过最小化卷积网络提取的特征标准差,使特征图失去信息,从而欺骗水印检测器。为应对3DGS模型庞大的搜索空间,采用基于群体的优化策略,将模型划分为多个独立子优化问题。实验表明,该框架能有效从主流3DGS水印方法中移除1维和2维水印,同时保持高视觉保真度。本工作揭示了现有3DGS版权保护方案的关键漏洞,呼吁发展更稳健的水印系统。
原文摘要 · Abstract (English)
With the rise of 3D Gaussian Splatting (3DGS), a variety of digital watermarking techniques, embedding either 1D bitstreams or 2D images, are used for copyright protection. However, the robustness of these watermarking techniques against potential attacks remains underexplored. This paper introduces the first universal black-box attack framework, the Group-based Multi-objective Evolutionary Attack (GMEA), designed to challenge these watermarking systems. We formulate the attack as a large-scale multi-objective optimization problem, balancing watermark removal with visual quality. In a black-box setting, we introduce an indirect objective function that blinds the watermark detector by minimizing the standard deviation of features extracted by a convolutional network, thus rendering the feature maps uninformative. To manage the vast search space of 3DGS models, we employ a group-based optimization strategy to partition the model into multiple, independent sub-optimization problems. Experiments demonstrate that our framework effectively removes both 1D and 2D watermarks from mainstream 3DGS watermarking methods while maintaining high visual fidelity. This work reveals critical vulnerabilities in existing 3DGS copyright protection schemes and calls for the development of more robust watermarking systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。