提出首个去水印视频检测基准,揭示现有检测器依赖水印而非真实生成特征。
RobustSora: De-Watermarked Benchmark for Robust AI-Generated Video Detection

- 构建包含4类6500段视频的基准,分离水印干扰因素
- 水印移除使检测准确率平均下降6.6个百分点(最高-14pp)
- 适合需评估检测器鲁棒性的研究人员与平台方
AI生成视频泛滥威胁信息真实性与数字信任。当前关键问题未被解决:商用生成器嵌入可见水印以追踪来源,但现有基准未控制此变量,导致检测器可能仅学习水印模式而非真实生成痕迹。本文提出RobustSora基准,包含6500段人工验证视频,分四类:真实无水印(A-C)、生成带水印(G-W)、生成去水印(G-DeW)、真实伪造带水印(A-S),数据源涵盖Vript、DVF、UltraVideo(真实)及Sora、Sora 2、Pika、Open-Sora 2、KLing(生成)。两个评测任务分别测试:任务一(水印去除鲁棒性)在移除水印的生成视频上评估检测效果;任务二(水印伪造鲁棒性)测量在真实视频中注入假水印时的误报率。十种模型(含专用检测器、Transformer分类器、多模态大模型)显示,水印操作导致准确率变化-9.4至+1.6个百分点(均值6.6pp;10模型中7个在两任务上均显著,p<0.01)。安慰剂对照组将修复伪影混淆控制在≤2pp,水印感知训练增强可恢复3-4pp,共同提供因果证据表明检测器主动依赖水印线索。按生成器拆解显示,Sora 2导致-11至-14pp下降,而Pika和Open-Sora 2仅-3至-6pp,说明水印显著性而非模型结构是依赖主因。研究呼吁在AIGC视频检测中引入水印感知评估与训练。数据集、代码及预训练模型将公开。
原文摘要 · Abstract (English)
The proliferation of AI-generated video models poses new challenges to information integrity and digital trust. A key confound, however, remains unaddressed: commercial generators embed visible overlay watermarks for provenance tracking, yet no existing benchmark controls for this variable, leaving open whether detectors learn genuine generation artefacts or merely associate watermark patterns with AI-generated labels. We present RobustSora, a benchmark of 6,500 manually verified videos in four categories: Authentic-Clean (A-C), Generated-Watermarked (G-W), Generated-DeWatermarked (G-DeW), and Authentic-Spoofed (A-S), sourced from Vript, DVF, and UltraVideo (authentic) and from Sora, Sora 2, Pika, Open-Sora 2, and KLing (generated). Two evaluation tasks isolate watermark effects: Task-I (Watermark Erasure Robustness) tests detection on watermark-removed AI videos; Task-II (Watermark Spoofing Robustness) measures false-alarm rates on authentic videos injected with fake watermarks. Across ten models spanning specialized detectors, transformer classifiers, and MLLMs, watermark manipulation induces accuracy changes of $-9.4$ to $+1.6$ pp (mean 6.6 pp; $p{<}0.01$ for 7/10 models on each task). A placebo control bounds inpainting-artefact confounds at $\le$2 pp, and a watermark-aware training augmentation recovers 3-4 pp on both tasks, together providing causal evidence that detectors actively rely on watermark cues. Per-generator breakdown shows that Sora 2 induces drops of $-11$ to $-14$ pp versus $-3$ to $-6$ pp for Pika and Open-Sora 2, indicating that watermark prominence, rather than detector architecture, is the principal driver of dependency. These results argue for watermark-aware evaluation and training in AIGC video detection. Dataset, evaluation code, and pretrained checkpoints will be released.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。