用新视角生成技术无痕擦除隐形水印,揭示现有水印机制的致命漏洞。
RAVEN: Erasing Invisible Watermarks via Novel View Synthesis
- 将水印移除转化为新视角合成问题,通过语义一致的视角变换实现无损去水印。
- 在15种水印方案上达到顶尖移除效果,且保持视觉质量优于现有方法。
- 无需水印知识或检测器,基于预训练模型零样本攻击,适合安全评估与防御研究。
隐形水印已成为认证AI生成图像内容的关键机制,主流平台已大规模部署。然而,评估这些方案对复杂移除攻击的脆弱性,对判断其可靠性并指导鲁棒设计至关重要。本文提出一种新思路:将水印移除重构为视角合成问题。核心洞察在于,生成同一语义内容的感知一致新视角(如同从不同位置重看场景),可自然消除嵌入水印,同时保持视觉保真度。这揭示了关键漏洞:水印虽能抵御像素域与频域攻击,却仍易受语义保留的视角变换影响。我们提出一种零样本扩散框架,在潜在空间施加可控几何变换,并引入视图引导对应注意力以维持重建结构一致性。该方法在冻结预训练模型下运行,无需检测器或水印知识,成功在15种水印方法上实现当前最优移除效果,超越14种基线攻击,且在多个数据集上保持优异感知质量。
原文摘要 · Abstract (English)
Invisible watermarking has become a critical mechanism for authenticating AI-generated image content, with major platforms deploying watermarking schemes at scale. However, evaluating the vulnerability of these schemes against sophisticated removal attacks remains essential to assess their reliability and guide robust design. In this work, we expose a fundamental vulnerability in invisible watermarks by reformulating watermark removal as a view synthesis problem. Our key insight is that generating a perceptually consistent alternative view of the same semantic content, akin to re-observing a scene from a shifted perspective, naturally removes the embedded watermark while preserving visual fidelity. This reveals a critical gap: watermarks robust to pixel-space and frequency-domain attacks remain vulnerable to semantic-preserving viewpoint transformations. We introduce a zero-shot diffusion-based framework that applies controlled geometric transformations in latent space, augmented with view-guided correspondence attention to maintain structural consistency during reconstruction. Operating on frozen pre-trained models without detector access or watermark knowledge, our method achieves state-of-the-art watermark suppression across 15 watermarking methods--outperforming 14 baseline attacks while maintaining superior perceptual quality across multiple datasets.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。