arXiv:2604.25491cs.CVcs.AI2026-04中稿 · IH&MMSEC 2026, Spe…被引 1

水印移除后会留下可被检测的统计痕迹,需同时考虑隐蔽性、效果和质量。

The Forensic Cost of Watermark Removal: From Dedicated Attacks to Image Editing

论文配图:The Forensic Cost of Watermark Removal: From Dedicated Attacks to Image Editing
图 1 · 摘自论文原文
  • 通过分析水印移除后的统计残留,提出新检测维度WRD
  • 在所有测试方法下,检测率超99.9%,误报率仅0.001%
  • 提醒攻击者需兼顾隐蔽性,适合安全与版权研究者

当前水印移除方法的评估仅关注攻击成功率和视觉质量,但我们发现这不够。最先进的攻击虽能无损地去除水印信号,却会在图像中留下独特的统计痕迹,暴露其操作历史。我们提出这一被忽视的评估维度——水印移除检测(WRD),并证明基于这些痕迹训练的现代分类器,在所有测试移除方法下均能达到超过99.9%的检测率,且在10⁻³误报率(FPR)下表现最优。现有任何攻击均未考虑此类取证泄露。我们在扩展的三重评估框架(攻击成功率、感知质量、取证可检测性)下,对主流水印方案与标准移除流程进行基准测试,发现目前无一方法能同时平衡三者。结果确立了取证隐蔽性作为水印移除的必要要求。

原文摘要 · Abstract (English)

Current watermark removal methods are evaluated on two axes: attack success rate and perceptual quality. We show this is insufficient. While state-of-the-art attacks successfully degrade the watermark signal without visible distortion, they leave distinct statistical artifacts that betray the removal attempt. We name this overlooked axis Watermark Removal Detection (WRD) and demonstrate that a modern classifier trained on these artifacts achieves state-of-the-art detection rates at $10^{-3}$ FPR across every removal method tested. No existing attack accounts for this forensic leakage. We benchmark leading watermarking schemes against standard removal pipelines under the extended evaluation triple of attack success, perceptual quality, and forensic detectability, and find that no current method balances all three. Our results establish forensic stealthiness as a necessary requirement for watermark removal.

水印检测取证分析模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。