扩散编辑会破坏水印,导致信息丢失,影响内容溯源。
When Denoising Becomes Unsigning: Theoretical and Empirical Analysis of Watermark Fragility Under Diffusion-Based Image Editing
- 将扩散编辑视为潜空间加噪+去噪过程,揭示水印衰减机制。
- 水印与编辑后图像的互信息随编辑强度增加趋近零,解码接近随机猜测。
- 适用于研究数字水印安全性和生成式内容治理的学者与开发者。
鲁棒隐形水印系统旨在嵌入不可感知的载荷,使其在常见的后期处理(如JPEG压缩、裁剪、加噪)后仍可解码。与此同时,基于扩散模型的图像编辑技术已迅速成熟,成为现代内容生产流程中的默认变换层,支持指令驱动编辑、对象插入与组合、交互式几何操作。本文研究了这一趋势之间一个微妙但日益重要的相互作用:扩散编辑可能无意中削弱甚至在极端情况下绕过为抵御传统失真而专门设计的鲁棒水印机制。我们提出一种统一视角,将扩散编辑器建模为在潜空间注入大量高斯噪声,并通过学习到的去噪动态投影回自然图像流形的过程。在此框架下,水印载荷表现为低能量、高频率信号,其在前向扩散步骤中被系统性衰减,随后在反向生成过程中被视为干扰噪声。我们使用信息论工具形式化该退化过程,证明对于广泛的像素级水印编码/解码器,水印载荷与编辑后输出之间的互信息随编辑强度增加趋近于零,解码误差接近随机猜测。我们通过一个现实的模拟实验协议和涵盖代表性水印方法与扩散编辑器的表格补充理论分析。最后,讨论伦理影响、负责任披露规范及面向生成式变换时代的水印设计指南。
原文摘要 · Abstract (English)
Robust invisible watermarking systems aim to embed imperceptible payloads that remain decodable after common post-processing such as JPEG compression, cropping, and additive noise. In parallel, diffusion-based image editing has rapidly matured into a default transformation layer for modern content pipelines, enabling instruction-based editing, object insertion and composition, and interactive geometric manipulation. This paper studies a subtle but increasingly consequential interaction between these trends: diffusion-based editing procedures may unintentionally compromise, and in extreme cases practically bypass, robust watermarking mechanisms that were explicitly engineered to survive conventional distortions. We develop a unified view of diffusion editors that (i) inject substantial Gaussian noise in a latent space and (ii) project back to the natural image manifold via learned denoising dynamics. Under this view, watermark payloads behave as low-energy, high-frequency signals that are systematically attenuated by the forward diffusion step and then treated as nuisance variation by the reverse generative process. We formalize this degradation using information-theoretic tools, proving that for broad classes of pixel-level watermark encoders/decoders the mutual information between the watermark payload and the edited output decays toward zero as the editing strength increases, yielding decoding error close to random guessing. We complement the theory with a realistic hypothetical experimental protocol and tables spanning representative watermarking methods and representative diffusion editors. Finally, we discuss ethical implications, responsible disclosure norms, and concrete design guidelines for watermarking schemes that remain meaningful in the era of generative transformations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。