为深度伪造内容嵌入不可见水印,实现创作时的源头可追溯
SAiW: Source-Attributable Invisible Watermarking for Proactive Deepfake Defense
- 水印嵌入基于源信息学习,生成可区分的数字签名
- 在多种攻击下仍保持鲁棒性,视觉失真极小
- 适合用于媒体可信溯源与主动防御场景
现代生成模型产生的深度伪造严重威胁信息真实性、数字身份与公众信任。现有检测方法多为被动响应,难以泛化于不断演化的生成技术。为此,本文提出SAiW——一种面向主动防御与媒体溯源的源归属不可见水印框架。不同于传统将水印视为通用信号的做法,SAiW将水印嵌入建模为源条件表示学习问题,水印身份编码来源并调制嵌入过程,生成具有辨识度的可追踪签名。通过特征级线性调制注入源信息,支持多源水印规模化生成;基于人类视觉系统先验设计的感知引导模块,确保扰动视觉不可察觉且具备鲁棒性。一个双用途取证解码器可同时重建水印并完成源归属,提供自动化验证与可解释的司法证据。在多个深度伪造数据集上的实验证明,SAiW在保持高感知质量的同时,对压缩、滤波、噪声、几何变换及对抗扰动均表现出强鲁棒性。通过在数字媒体中绑定不可见但可验证的标记,实现可靠认证与源归属,为主动防御与可信媒体溯源提供可扩展基础。
原文摘要 · Abstract (English)
Deepfakes generated by modern generative models pose a serious threat to information integrity, digital identity, and public trust. Existing detection methods are largely reactive, attempting to identify manipulations after they occur and often failing to generalize across evolving generation techniques. This motivates the need for proactive mechanisms that secure media authenticity at the time of creation. In this work, we introduce SAiW, a Source-Attributed Invisible watermarking Framework for proactive deepfake defense and media provenance verification. Unlike conventional watermarking methods that treat watermark payloads as generic signals, SAiW formulates watermark embedding as a source-conditioned representation learning problem, where watermark identity encodes the originating source and modulates the embedding process to produce discriminative and traceable signatures. The framework integrates feature-wise linear modulation to inject source identity into the embedding network, enabling scalable multi-source watermark generation. A perceptual guidance module derived from human visual system priors ensures that watermark perturbations remain visually imperceptible while maintaining robustness. In addition, a dual-purpose forensic decoder simultaneously reconstructs the embedded watermark and performs source attribution, providing both automated verification and interpretable forensic evidence. Extensive experiments across multiple deepfake datasets demonstrate that SAiW achieves high perceptual quality while maintaining strong robustness against compression, filtering, noise, geometric transformations, and adversarial perturbations. By binding digital media to its origin through invisible yet verifiable markers, SAiW enables reliable authentication and source attribution, providing a scalable foundation for proactive deepfake defense and trustworthy media provenance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。