提出针对数字人水印的鲁棒性评测基准与新方法
RAW: Robust Avatar Watermarking -- Benchmarking and Baseline

- 在3D人脸重建的UV纹理空间嵌入水印,提升抗干扰能力
- 对背景移除攻击水印恢复率达95.6%,缩放攻击达92.4%
- 首个专为数字人设计的水印评测基准,适合研究者参考
数字人水印面临独特挑战:部署前常经历背景替换、画面裁剪和格式转换等后处理。本文提出RAW(Robust Avatar Watermarking)基准,包含50个来自5家商业提供商的合成数字人视频,以及6种模拟真实工作流的攻击方式。评估7种现有方法发现,背景移除等特定于数字人的攻击会显著降低水印恢复效果。为此提出WALT(Watermarking Avatars with Learned Textures),通过3D人脸重建在UV纹理空间嵌入水印。WALT在缩放攻击下保持92.4%的恢复率,在背景移除攻击下达到95.6%的高鲁棒性。研究数据集已公开,以推动数字人水印技术发展。
原文摘要 · Abstract (English)
Digital avatar watermarking presents unique challenges: avatars are routinely post-processed with background replacement, reframing, and format conversion before deployment. We introduce \textbf{RAW} (Robust Avatar Watermarking), a benchmark comprising 50 synthetic avatar videos from 5 commercial providers and 6 attacks simulating real-world avatar workflows. Evaluating 7 existing methods reveals that avatar-specific attacks such as background removal significantly degrade watermark recovery. We propose \textbf{WALT} (Watermarking Avatars with Learned Textures), which embeds watermarks in UV texture space via 3D face reconstruction. WALT achieves the highest robustness to zoom attacks (92.4\%) while maintaining strong performance on background removal (95.6\%). We release our benchmark to facilitate research into avatar-specific watermarking.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。