提出首个解耦表征的图水印框架,提升水印鲁棒性与透明性
DRGW: Learning Disentangled Representations for Robust Graph Watermarking
- 通过对抗训练编码器学习不变结构表征,分离出独立水印载体
- 设计可逆神经网络实现无损水印嵌入提取,检测率接近100%
- 引入结构感知编辑器,有效抵御图结构扰动,适合版权保护场景
图结构数据是众多网络应用的基础,水印技术对于保护知识产权和确保数据溯源至关重要。现有方法主要基于图结构或纠缠的图表示,由于图表示中的信息耦合以及连续数值表示到图结构转换时不可控的离散化,导致水印透明性和鲁棒性受损。为此,我们提出DRGW,首个通过解耦表征学习解决这些问题的图水印框架。具体而言,我们设计了一个对抗训练的编码器,学习对多种扰动具有不变性的结构表示,并推导出统计独立的水印载体,确保水印的鲁棒性与透明性。同时,我们开发了一种图感知的可逆神经网络,提供无损的水印嵌入与提取通道,保证高可检测性和透明性。此外,我们设计了结构感知编辑器,将潜在修改分解为离散的图编辑操作,增强对结构扰动的鲁棒性。在多个基准数据集上的实验表明,DRGW表现出卓越的有效性。
原文摘要 · Abstract (English)
Graph-structured data is foundational to numerous web applications, and watermarking is crucial for protecting their intellectual property and ensuring data provenance. Existing watermarking methods primarily operate on graph structures or entangled graph representations, which compromise the transparency and robustness of watermarks due to the information coupling in representing graphs and uncontrollable discretization in transforming continuous numerical representations into graph structures. This motivates us to propose DRGW, the first graph watermarking framework that addresses these issues through disentangled representation learning. Specifically, we design an adversarially trained encoder that learns an invariant structural representation against diverse perturbations and derives a statistically independent watermark carrier, ensuring both robustness and transparency of watermarks. Meanwhile, we devise a graph-aware invertible neural network to provide a lossless channel for watermark embedding and extraction, guaranteeing high detectability and transparency of watermarks. Additionally, we develop a structure-aware editor that resolves the issue of latent modifications into discrete graph edits, ensuring robustness against structural perturbations. Experiments on diverse benchmark datasets demonstrate the superior effectiveness of DRGW.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。