arXiv:2602.20053cs.CV2026-02被引 1

提出分阶段防御框架,显著提升水印图像在攻击下的鲁棒性与清晰度。

Decoupling Defense Strategies for Robust Image Watermarking

  • 分两阶段优化:先专注抗对抗攻击,再处理畸变与重生成攻击。
  • 在三种攻击下分别提升29%、33%、46%的识别准确率。
  • 适合需要高保真且强鲁棒性的数字水印应用场景。

基于深度学习的图像水印虽对常规失真具备鲁棒性,但仍易受先进对抗攻击和重生成攻击影响。传统方法联合优化编码器与解码器,存在两个固有缺陷:(1) 解码器对抗训练导致干净图像准确率下降;(2) 同时训练三类攻击使鲁棒性受限。为此,我们提出AdvMark,一种新型两阶段微调框架,实现防御策略解耦。第一阶段通过定制化对抗训练,仅条件性更新解码器,主要微调编码器,将图像映射至不可攻击区域,而非修改决策边界,从而保留干净准确率。第二阶段通过直接图像优化应对畸变与重生成攻击,设计具有理论保障的约束图像损失函数,平衡与原始图像及编码图像的偏差。同时引入质量感知早停机制,确保视觉质量下限。大量实验表明,AdvMark在图像质量与全面鲁棒性上均优于现有方法,对畸变、重生成和对抗攻击的识别准确率分别提升最高达29%、33%和46%。

原文摘要 · Abstract (English)

Deep learning-based image watermarking, while robust against conventional distortions, remains vulnerable to advanced adversarial and regeneration attacks. Conventional countermeasures, which jointly optimize the encoder and decoder via a noise layer, face 2 inevitable challenges: (1) decrease of clean accuracy due to decoder adversarial training and (2) limited robustness due to simultaneous training of all three advanced attacks. To overcome these issues, we propose AdvMark, a novel two-stage fine-tuning framework that decouples the defense strategies. In stage 1, we address adversarial vulnerability via a tailored adversarial training paradigm that primarily fine-tunes the encoder while only conditionally updating the decoder. This approach learns to move the image into a non-attackable region, rather than modifying the decision boundary, thus preserving clean accuracy. In stage 2, we tackle distortion and regeneration attacks via direct image optimization. To preserve the adversarial robustness gained in stage 1, we formulate a principled, constrained image loss with theoretical guarantees, which balances the deviation from cover and previous encoded images. We also propose a quality-aware early-stop to further guarantee the lower bound of visual quality. Extensive experiments demonstrate AdvMark outperforms with the highest image quality and comprehensive robustness, i.e. up to 29\%, 33\% and 46\% accuracy improvement for distortion, regeneration and adversarial attacks, respectively.

水印对抗攻击图像优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。