用隐式水印实现人脸修复与篡改定位,防伪更精准。
High-Fidelity Face Content Recovery via Tamper-Resilient Versatile Watermarking
- 用紧凑语义潜变量做水印,保留原图细节。
- 无专用定位信号仍可精确定位篡改区域。
- 模拟真实伪造流程,增强对AI换脸的鲁棒性。
AIGC驱动的人脸篡改和深度伪造严重威胁媒体来源真实性、完整性与版权保护。现有通用水印系统通常依赖显式定位信号,导致画质下降且在强生成编辑下解码鲁棒性减弱。此外,这些方法很少支持内容恢复,难以重建原始证据。为此,我们提出VeriFi框架,统一实现版权保护、像素级篡改定位与高保真人脸内容恢复。其三大贡献为:(1)嵌入紧凑语义潜变量水印,作为内容保持先验,支持严重篡改后的忠实还原;(2)无需专用定位信号,通过图像特征与解码溯源信号相关性实现细粒度定位;(3)引入AIGC攻击模拟器,结合潜在空间混合与无缝融合,提升对真实深度伪造流程的鲁棒性。在CelebA-HQ与FFHQ上的大量实验表明,VeriFi在水印鲁棒性、定位准确率与恢复质量上均优于现有最优基线,为深度伪造取证提供实用且可验证的防御方案。
原文摘要 · Abstract (English)
The proliferation of AIGC-driven face manipulation and deepfakes poses severe threats to media provenance, integrity, and copyright protection. Existing versatile watermarking systems typically rely on embedding explicit localization payloads, which introduces a fidelity--functionality trade-off: larger localization signals degrade visual quality and often reduce decoding robustness under strong generative edits. Moreover, these methods rarely support content recovery, limiting their forensic value when original evidence must be reconstructed. To address these challenges, we present VeriFi, a versatile watermarking framework that unifies copyright protection, pixel-level manipulation localization, and high-fidelity face content recovery. VeriFi makes three key contributions: (1) it embeds a compact semantic latent watermark that serves as a content-preserving prior, enabling faithful restoration even after severe manipulations; (2) it achieves fine-grained localization without dedicated payloads by correlating image features with decoded provenance signals; and (3) it introduces an AIGC attack simulator that combines latent-space mixing with seamless blending to enhance robustness against realistic deepfake pipelines. Extensive experiments on CelebA-HQ and FFHQ demonstrate that VeriFi consistently outperforms state-of-the-art baselines in watermark robustness, localization accuracy, and recovery quality, providing a practical and verifiable defense for deepfake forensics.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。