通过特征一致性元学习,提升水印模型在复杂干扰下的鲁棒性与泛化能力。
Meta-FC: Meta-Learning with Feature Consistency for Robust and Generalizable Watermarking
- 采用多干扰组合的元学习策略,让模型学习跨干扰的稳定特征。
- 在强干扰、组合干扰和未知干扰下,平均性能提升1.59%~4.71%。
- 适合追求高鲁棒性的图像水印系统设计者使用。
近年来基于深度学习的水印技术取得了显著进展。为增强对各类干扰的鲁棒性,现有方法通常采用单随机干扰(SRD)策略,即每批次训练中仅选择一种随机干扰作为噪声层。然而,该策略将干扰独立处理,忽视了不同干扰间的内在关联,导致批次间优化冲突,限制了水印模型的鲁棒性与泛化能力。为此,本文提出一种新训练策略——特征一致性元学习(Meta-FC)。具体地,从噪声池中随机采样多种干扰构成元训练任务,同时保留一种干扰作为模拟“未知”干扰用于元测试。通过元学习,模型被引导识别在不同干扰下仍保持稳定激活的神经元,缓解因批次内多样干扰随机采样带来的优化冲突。为进一步促进稳定激活转化为干扰不变表示,引入特征一致性损失,约束同一图像在不同干扰下解码特征的一致性。大量实验表明,相比SRD策略,Meta-FC在高强干扰、组合干扰及未知干扰下,平均提升水印模型鲁棒性与泛化能力1.59%、4.71%和2.38%。
原文摘要 · Abstract (English)
Deep learning-based watermarking has made remarkable progress in recent years. To achieve robustness against various distortions, current methods commonly adopt a training strategy where a \underline{\textbf{s}}ingle \underline{\textbf{r}}andom \underline{\textbf{d}}istortion (SRD) is chosen as the noise layer in each training batch. However, the SRD strategy treats distortions independently within each batch, neglecting the inherent relationships among different types of distortions and causing optimization conflicts across batches. As a result, the robustness and generalizability of the watermarking model are limited. To address this issue, we propose a novel training strategy that enhances robustness and generalization via \underline{\textbf{meta}}-learning with \underline{\textbf{f}}eature \underline{\textbf{c}}onsistency (Meta-FC). Specifically, we randomly sample multiple distortions from the noise pool to construct a meta-training task, while holding out one distortion as a simulated ``unknown'' distortion for the meta-testing phase. Through meta-learning, the model is encouraged to identify and utilize neurons that exhibit stable activations across different types of distortions, mitigating the optimization conflicts caused by the random sampling of diverse distortions in each batch. To further promote the transformation of stable activations into distortion-invariant representations, we introduce a feature consistency loss that constrains the decoded features of the same image subjected to different distortions to remain consistent. Extensive experiments demonstrate that, compared to the SRD training strategy, Meta-FC improves the robustness and generalization of various watermarking models by an average of 1.59\%, 4.71\%, and 2.38\% under high-intensity, combined, and unknown distortions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。