将图像语义分解嵌入噪声,实现细粒度防篡改水印。
SLICE: Semantic Latent Injection via Compartmentalized Embedding for Image Watermarking
- 分四类语义因子绑定到噪声特定区域,实现精准锚定。
- 对语义篡改攻击检测成功率超95%,误接受率极低。
- 无需训练,适合真实场景下的图像溯源与篡改定位。
通过在扩散模型的初始噪声中嵌入水印,可为图像溯源提供新思路,但内容无关的噪声模式易被反演和再生攻击伪造。现有语义感知水印方法依赖单一全局语义绑定,对局部但整体一致的语义编辑仍脆弱。为此,我们提出SLICE框架,将图像语义解耦为四类因子(主体、环境、动作、细节),并精确锚定至初始高斯噪声的特定区域。该细粒度语义绑定支持高级水印验证,可检测并定位语义篡改。理论证明了其鲁棒性与误接受率的统计保障。实验表明,面对先进语义引导的再生攻击,SLICE显著优于现有基线,攻击成功率大幅降低,同时保持图像质量和语义保真度。总体而言,SLICE提供了实用、无需训练的溯源方案,兼具精细诊断能力与对抗真实攻击的鲁棒性。
原文摘要 · Abstract (English)
Watermarking the initial noise of diffusion models has emerged as a promising approach for image provenance, but content-independent noise patterns can be forged via inversion and regeneration attacks. Recent semantic-aware watermarking methods improve robustness by conditioning verification on image semantics. However, their reliance on a single global semantic binding makes them vulnerable to localized but globally coherent semantic edits. To address this limitation and provide a trustworthy semantic-aware watermark, we propose $\underline{\textbf{S}}$emantic $\underline{\textbf{L}}$atent $\underline{\textbf{I}}$njection via $\underline{\textbf{C}}$ompartmentalized $\underline{\textbf{E}}$mbedding ($\textbf{SLICE}$). Our framework decouples image semantics into four semantic factors (subject, environment, action, and detail) and precisely anchors them to distinct regions in the initial Gaussian noise. This fine-grained semantic binding enables advanced watermark verification where semantic tampering is detectable and localizable. We theoretically justify why SLICE enables robust and reliable tamper localization and provides statistical guarantees on false-accept rates. Experimental results demonstrate that SLICE significantly outperforms existing baselines against advanced semantic-guided regeneration attacks, substantially reducing attack success while preserving image quality and semantic fidelity. Overall, SLICE offers a practical, training-free provenance solution that is both fine-grained in diagnosis and robust to realistic adversarial manipulations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。