提出无损水印框架NiMark,有效抵抗屏幕截图攻击。
NiMark: A Non-intrusive Watermarking Framework against Screen-shooting Attacks
- 用SG-XOR估计器强制图像与水印的严格绑定
- 两阶段训练结合修复器,提升对屏幕噪声的鲁棒性
- 零视觉失真下仍优于现有方法,适合高安全场景
未经授权的屏幕截图带来严重数据泄露风险。传统水印为抵御此类攻击需强嵌入,但会损害图像质量。非侵入式水印通过构建逻辑验证密钥实现无损保护,但现有方案难以应对屏幕截图带来的噪声。尽管深度学习有潜力解决此问题,我们发现直接应用会导致一种未被充分关注的失败模式——结构捷径:网络倾向于学习平凡的恒等映射,忽略图像与水印的关联。即使强制逻辑绑定,标准训练策略也无法完全弥合噪声差距,导致对物理失真的鲁棒性不足。为此,本文提出端到端的NiMark框架。首先,引入Sigmoid-Gated XOR(SG-XOR)估计器,实现逻辑操作的梯度传播,有效强制图像-水印的刚性绑定;其次,设计两阶段训练策略,融合修复器以弥补屏幕截图噪声引起的域偏移。实验表明,NiMark在数字攻击和屏幕截图噪声下均持续优于代表性先进方法,同时保持零视觉失真。
原文摘要 · Abstract (English)
Unauthorized screen-shooting poses a critical data leakage risk. Resisting screen-shooting attacks typically requires high-strength watermark embedding, inevitably degrading the cover image. To resolve the robustness-fidelity conflict, non-intrusive watermarking has emerged as a solution by constructing logical verification keys without altering the original content. However, existing non-intrusive schemes lack the capacity to withstand screen-shooting noise. While deep learning offers a potential remedy, we observe that directly applying it leads to a previously underexplored failure mode, the Structural Shortcut: networks tend to learn trivial identity mappings and neglect the image-watermark binding. Furthermore, even when logical binding is enforced, standard training strategies cannot fully bridge the noise gap, yielding suboptimal robustness against physical distortions. In this paper, we propose NiMark, an end-to-end framework addressing these challenges. First, to eliminate the structural shortcut, we introduce the Sigmoid-Gated XOR (SG-XOR) estimator to enable gradient propagation for the logical operation, effectively enforcing rigid image-watermark binding. Second, to overcome the robustness bottleneck, we devise a two-stage training strategy integrating a restorer to bridge the domain gap caused by screen-shooting noise. Experiments demonstrate that NiMark consistently outperforms representative state-of-the-art methods against both digital attacks and screen-shooting noise, while maintaining zero visual distortion.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。