经典水印在真实场景中比现代方法更安全可靠
Do Modern Post-Hoc Watermarking Methods Beat Broken-Arrows?

- 对比经典与现代后处理水印在真实攻击下的表现
- 经典方法在安全性和鲁棒性上均优于现代方案
- 适合关注生成内容溯源安全性的研究者
随着扩散模型等生成模型的快速普及,数字水印已成为识别AI生成图像的关键技术。现代后处理水印方案利用神经网络实现极低的误报率,同时对常见图像变换具有鲁棒性。然而,现有研究缺乏对现代方法与经典方法在真实场景下的对比,尤其在安全性优先于极低误报率的场景中。本文针对多种经典图像增强和近期复杂攻击,公平比较了现代与经典后处理水印在鲁棒性与安全性方面的表现。实验结果表明,在真实场景下,经典水印在保持鲁棒性的同时,安全性能显著优于现代技术。
原文摘要 · Abstract (English)
With the rapid proliferation of generative models, such as diffusion models, digital watermarking has emerged as a crucial solution for identifying AI-generated images. Modern post-hoc watermarking schemes use neural networks to achieve an extremely low false-alarm rate while remaining robust to common image transformations. However, there is a lack of comparison between these modern methods and classic ones, particularly in real-world scenarios where robustness and security take precedence over achieving an extremely low false-alarm probability. In this paper, we propose a fair comparison of robustness and security between modern and classic post-hoc watermarking across various types of classic augmentations and recent sophisticated attacks. Our experiments show that, in a realistic scenario, classic watermarking outperforms modern techniques in terms of security while maintaining robustness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。