扩散模型可有效破坏鲁棒水印,实现无损图像再生
Diffusion-Based Image Editing for Breaking Robust Watermarks
- 利用扩散模型的图像再生过程消除水印信号
- 攻击后水印恢复率接近零,图像视觉质量仍高
- 揭示现有水印技术在生成式AI下的根本漏洞
鲁棒隐形水印旨在将隐藏信息嵌入图像,使其能抵抗各类图像操作。然而,强大的基于扩散的图像生成与编辑技术对这类水印方案构成新威胁。本文从理论和方法两方面证明,扩散模型能有效破坏针对传统扰动设计的鲁棒水印。我们展示,扩散驱动的“图像再生”过程可在保留感知内容的同时抹除嵌入水印。进一步提出一种新型引导扩散攻击,在生成过程中显式针对水印信号,显著降低水印可检测性。理论上,我们证明当图像经历充分的扩散变换后,水印图像与嵌入水印内容之间的互信息趋于消失,导致解码失败。实验上,我们在多个先进水印方案(包括StegaStamp、TrustMark和VINE等深度学习方法)上验证该方法,攻击后水印恢复率接近零,同时保持再生图像的高视觉保真度。研究结果揭示了当前鲁棒水印技术在生成式人工智能时代的根本缺陷,强调了构建新水印策略的紧迫性。
原文摘要 · Abstract (English)
Robust invisible watermarking aims to embed hidden information into images such that the watermark can survive various image manipulations. However, the rise of powerful diffusion-based image generation and editing techniques poses a new threat to these watermarking schemes. In this paper, we present a theoretical study and method demonstrating that diffusion models can effectively break robust image watermarks that were designed to resist conventional perturbations. We show that a diffusion-driven ``image regeneration'' process can erase embedded watermarks while preserving perceptual image content. We further introduce a novel guided diffusion attack that explicitly targets the watermark signal during generation, significantly degrading watermark detectability. Theoretically, we prove that as an image undergoes sufficient diffusion-based transformation, the mutual information between the watermarked image and the embedded watermark payload vanishes, resulting in decoding failure. Experimentally, we evaluate our approach on multiple state-of-the-art watermarking schemes (including the deep learning-based methods StegaStamp, TrustMark, and VINE) and demonstrate near-zero watermark recovery rates after attack, while maintaining high visual fidelity of the regenerated images. Our findings highlight a fundamental vulnerability in current robust watermarking techniques against generative model-based attacks, underscoring the need for new watermarking strategies in the era of generative AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。