arXiv:2511.11295cs.CV2025-11

不依赖噪声模拟,利用低频特征实现抗编辑鲁棒水印

SimuFreeMark: A Noise-Simulation-Free Robust Watermarking Against Image Editing

  • 直接在图像低频特征空间嵌入水印,避免训练时的噪声模拟
  • 在多种常规与语义编辑攻击下,水印保留率优于现有方法
  • 适合需要高鲁棒性且视觉质量要求高的内容版权保护场景

人工智能生成内容(AIGC)的快速发展带来了对鲁棒图像水印的迫切需求,以抵御传统信号处理和新型语义编辑攻击。当前基于深度学习的方法依赖手工设计的噪声模拟层进行训练,这限制了其对未知失真的泛化能力。本文提出SimuFreeMark,一种无噪声模拟的鲁棒水印框架,通过利用图像低频成分的固有稳定性克服该局限。我们系统证明了低频成分对各类攻击具有显著鲁棒性。在此基础上,SimuFreeMark将水印直接嵌入低频成分的深度特征空间,借助预训练变分自编码器(VAE)将水印与结构稳定的图像表示绑定,完全消除训练中对噪声模拟的需求。大量实验表明,SimuFreeMark在多种常规与语义攻击下均优于当前最优方法,同时保持优异的视觉质量。

原文摘要 · Abstract (English)

The advancement of artificial intelligence generated content (AIGC) has created a pressing need for robust image watermarking that can withstand both conventional signal processing and novel semantic editing attacks. Current deep learning-based methods rely on training with hand-crafted noise simulation layers, which inherently limit their generalization to unforeseen distortions. In this work, we propose $\textbf{SimuFreeMark}$, a noise-$\underline{\text{simu}}$lation-$\underline{\text{free}}$ water$\underline{\text{mark}}$ing framework that circumvents this limitation by exploiting the inherent stability of image low-frequency components. We first systematically establish that low-frequency components exhibit significant robustness against a wide range of attacks. Building on this foundation, SimuFreeMark embeds watermarks directly into the deep feature space of the low-frequency components, leveraging a pre-trained variational autoencoder (VAE) to bind the watermark with structurally stable image representations. This design completely eliminates the need for noise simulation during training. Extensive experiments demonstrate that SimuFreeMark outperforms state-of-the-art methods across a wide range of conventional and semantic attacks, while maintaining superior visual quality.

图像水印鲁棒性低频特征VAE

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。