DeMark无需查询即可攻破深度伪造水印,让检测率从100%降至32.9%
DeMark: A Query-Free Black-Box Attack on Deepfake Watermarking Defenses
- 通过压缩感知稀疏化,从潜在空间压制水印信号
- 在8种主流水印方案上平均将检测准确率降至32.9%
- 适合研究水印安全性和对抗攻击的学者参考
深度伪造的快速泛滥引发了对其滥用的担忧,促使在合成图像中使用防御性水印以实现可靠检测和溯源。然而,这一防御范式假设水印具有内在抗移除性。我们通过DeMark框架挑战这一假设,该框架是一种针对深度伪造防御性图像水印方案的无查询黑盒攻击方法。DeMark利用编码器-解码器水印模型中的潜在空间漏洞,通过基于压缩感知的稀疏化过程抑制水印信号,同时保持深度伪造所需的感知与结构真实感。在八种最先进的水印方案上,DeMark将水印检测准确率平均从100%降至32.9%,且视觉质量自然,优于现有攻击方法。我们进一步评估了三种防御策略(图像超分辨率、稀疏水印、对抗训练),发现它们基本无效。结果表明,当前编码器-解码器水印方案仍易受潜在空间操纵,凸显了开发更鲁棒水印方法以防范深度伪造的紧迫性。
原文摘要 · Abstract (English)
The rapid proliferation of realistic deepfakes has raised urgent concerns over their misuse, motivating the use of defensive watermarks in synthetic images for reliable detection and provenance tracking. However, this defense paradigm assumes such watermarks are inherently resistant to removal. We challenge this assumption with DeMark, a query-free black-box attack framework that targets defensive image watermarking schemes for deepfakes. DeMark exploits latent-space vulnerabilities in encoder-decoder watermarking models through a compressive sensing based sparsification process, suppressing watermark signals while preserving perceptual and structural realism appropriate for deepfakes. Across eight state-of-the-art watermarking schemes, DeMark reduces watermark detection accuracy from 100% to 32.9% on average while maintaining natural visual quality, outperforming existing attacks. We further evaluate three defense strategies, including image super resolution, sparse watermarking, and adversarial training, and find them largely ineffective. These results demonstrate that current encoder decoder watermarking schemes remain vulnerable to latent-space manipulations, underscoring the need for more robust watermarking methods to safeguard against deepfakes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。