用深度学习生成可验证水印,实现图像真伪自动检测。
DeepSignature: Digitally Signed, Content-Encoding Watermarks for Robust and Transparent Image Authentication

- 用神经网络生成内容相关水印并嵌入图像
- 对伪造攻击识别率接近100%
- 支持客户端验证,适合版权保护与可信传播
AI生成模型极大拓展了图像编辑与创作的可能,虚假来源的图像严重威胁公众对图像真实性的信任。本文提出DeepSignature,将数字签名保障与深度神经网络能力结合:利用神经网络生成内容编码水印,并不可察觉地嵌入图像,同时确保水印可稳健提取。水印具备密码学可验证性,支持来源追溯与完整性校验。该方法兼容现有图像格式,无需特殊处理,支持仅凭签名者公钥的客户端验证。我们还提出一种新型潜在空间验证方法,用于检测并定位篡改行为。评估涵盖不可察觉性、良性变换鲁棒性、伪造检测及多种攻击场景下的抗性。实验表明,DeepSignature能可靠识别重大伪造行为,识别率接近100%。其模块化设计和可调参数使其可适配不同应用需求。代码与模型权重将公开。
原文摘要 · Abstract (English)
AI-powered generative models have significantly expanded the possibilities for editing, manipulating, and creating high-quality images. Particularly, images that falsely appear to originate from trusted sources pose a serious threat, undermining public trust in image authenticity. We propose DeepSignature, a novel approach that integrates the guarantees of digital signatures with the capabilities of deep neural networks. Neural networks are used both to generate content-encoding watermarks and to embed them imperceptibly into images while ensuring robust extraction. These watermarks are cryptographically verifiable, enabling source attribution and image integrity validation. DeepSignature is compatible with existing image formats and requires no special handling of signed images. It supports client-side verification, requiring only the signer's public key. Additionally, we introduce a novel latent-space verification approach to detect and localize tampering attempts. We evaluate DeepSignature in terms of imperceptibility, robustness to benign transformations, forgery detection, and its resilience against various attack scenarios. Our results highlight the inherent trade-offs between imperceptibility, robustness, and integrity verification. We demonstrate that DeepSignature reliably identifies significant forgery attempts -- achieving near 100\% in our experiments. Finally, we emphasize DeepSignature's modularity and tunable parameters, allowing adaptation to application-specific requirements. Code and model weights will be published.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。