arXiv:2508.17247cs.CV2025-08AAAI被引 6

发现并防御深度伪造中多重水印攻击,保障溯源水印不被破坏

Uncovering and Mitigating Destructive Multi-Embedding Attacks in Deepfake Proactive Forensics

  • 通过模拟多重嵌入攻击场景,训练模型生成稀疏稳定的水印
  • 在二次嵌入后仍能正确提取原始水印,鲁棒性显著提升
  • 可即插即用,适用于多种现有溯源方法,适合隐私保护场景

随着深度伪造技术快速发展和数字媒体广泛传播,个人隐私面临严重安全威胁。深度伪造主动取证通过嵌入难以察觉的水印实现可靠溯源,是关键防御手段。然而现有方法依赖单一水印嵌入的理想假设,现实场景中并不成立。本文首次正式定义并证实了多重嵌入攻击(MEA)的存在:当已保护图像再次被嵌入水印时,原始水印可能被破坏或移除,导致整个取证机制失效。为应对这一漏洞,我们提出一种通用训练范式——对抗干扰模拟(AIS)。该方法在微调阶段显式模拟MEA场景,并引入韧性驱动损失函数,促使模型学习稀疏且稳定的水印表示。实验表明,AIS训练范式可有效提升多种现有方法对MEA的鲁棒性,且无需修改网络结构,具备即插即用特性。

原文摘要 · Abstract (English)

With the rapid evolution of deepfake technologies and the wide dissemination of digital media, personal privacy is facing increasingly serious security threats. Deepfake proactive forensics, which involves embedding imperceptible watermarks to enable reliable source tracking, serves as a crucial defense against these threats. Although existing methods show strong forensic ability, they rely on an idealized assumption of single watermark embedding, which proves impractical in real-world scenarios. In this paper, we formally define and demonstrate the existence of Multi-Embedding Attacks (MEA) for the first time. When a previously protected image undergoes additional rounds of watermark embedding, the original forensic watermark can be destroyed or removed, rendering the entire proactive forensic mechanism ineffective. To address this vulnerability, we propose a general training paradigm named Adversarial Interference Simulation (AIS). Rather than modifying the network architecture, AIS explicitly simulates MEA scenarios during fine-tuning and introduces a resilience-driven loss function to enforce the learning of sparse and stable watermark representations. Our method enables the model to maintain the ability to extract the original watermark correctly even after a second embedding. Extensive experiments demonstrate that our plug-and-play AIS training paradigm significantly enhances the robustness of various existing methods against MEA.

深度伪造水印溯源鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。