测试生成图像水印在语义修改下的鲁棒性,发现视觉质量高时水印常失效。
Understanding Semantic Perturbations on In-Processing Generative Image Watermarks
- 用现成模型生成语义改变但视觉几乎不变的图像,系统测试水印稳定性。
- 多数水印在语义编辑后检测率降至接近零,尽管图像质量保持良好。
- 提醒研究者需将语义篡改纳入水印评估,避免过度乐观结论。
高保真生成模型的广泛应用加剧了对内容来源认证机制的需求。在处理过程中嵌入签名的生成式水印被提出作为解决方案,常宣称对几何变换和滤波等常规后处理具有鲁棒性。然而,对改变高层场景内容但保持合理视觉质量的语义操作的鲁棒性尚未充分研究。本文提出一个简单、多阶段框架,系统测试生成水印在语义漂移下的表现。该框架利用现成的目标检测、掩码生成及语义引导修复/重生成模型,实现控制性强、语义改变明显的编辑,同时感知失真极小。基于对代表性方案的广泛实验,我们发现水印鲁棒性显著依赖于语义纠缠程度:某些在常规扰动下仍可检测的水印,在语义编辑下会失效,许多情况下检测率降至接近零,而图像质量仍维持高位。整体结果揭示当前水印评估存在关键缺口,表明水印设计与基准测试必须明确考虑对语义操作的鲁棒性。
原文摘要 · Abstract (English)
The widespread deployment of high-fidelity generative models has intensified the need for reliable mechanisms for provenance and content authentication. In-processing watermarking, embedding a signature into the generative model's synthesis procedure, has been advocated as a solution and is often reported to be robust to standard post-processing (such as geometric transforms and filtering). Yet robustness to semantic manipulations that alter high-level scene content while maintaining reasonable visual quality is not well studied or understood. We introduce a simple, multi-stage framework for systematically stress-testing in-processing generative watermarks under semantic drift. The framework utilizes off-the-shelf models for object detection, mask generation, and semantically guided inpainting or regeneration to produce controlled, meaning-altering edits with minimal perceptual degradation. Based on extensive experiments on representative schemes, we find that robustness varies significantly with the degree of semantic entanglement: methods by which watermarks remain detectable under a broad suite of conventional perturbations can fail under semantic edits, with watermark detectability in many cases dropping to near zero while image quality remains high. Overall, our results reveal a critical gap in current watermarking evaluations and suggest that watermark designs and benchmarking must explicitly account for robustness against semantic manipulation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。