arXiv:2607.27800cs.CV2026-07

提出分频扩散网络,精准去除水印同时保持图像质量。

FDDWAN: A Frequency-Decoupled Diffusion Network for Watermarking Attack

论文配图:FDDWAN: A Frequency-Decoupled Diffusion Network for Watermarking Attack
图 1 · 摘自论文原文
  • 分频域攻击:低频高频分别处理,针对性抑制水印
  • 残差扩散机制,仅修复残留差异,减少图像失真
  • 在多个数据集上优于传统和学习型方法,适合高保真去水印场景

现有不可见水印移除方法常难以准确捕捉含水印特征,导致水印消除与视觉保真度之间存在不良权衡。本文提出频率解耦扩散水印攻击网络(FDDWAN),一种从粗到精的框架,通过小波域分解与残差扩散优化实现水印移除。初始阶段,基于小波的频域初步攻击模块(WFPAM)将含水印图像分解为低频和高频子带,并针对其对水印鲁棒性与感知质量的不同贡献,采用特定攻击策略。后续阶段,频域残差扩散攻击模块(FRDAM)在训练中分别建模初步攻击输出与无水印参考图之间的残差分布。不同于重建整张图像,FRDAM仅选择性地细化频域残差,引导扩散过程聚焦于残留水印相关差异,同时最小化对图像内容的修改。在CelebA和ImageNet上,针对四种代表性水印方案的大量实验表明,FDDWAN在水印移除效果与视觉保真度之间实现了更优权衡,优于传统及基于学习的攻击方法。

原文摘要 · Abstract (English)

Existing invisible watermark removal methods often struggle to accurately capture the watermark-bearing features, leading to an unfavorable trade-off between watermark suppression and perceptual fidelity. In this paper, we propose the Frequency-Decoupled Diffusion Watermark Attack Network (FDDWAN), a coarse-to-fine framework that performs watermark removal through wavelet-domain decomposition and residual diffusion refinement. In the initial stage, the Wavelet-based Frequency-domain Preliminary Attack Module (WFPAM) decomposes the watermarked image into low- and high-frequency subbands and applies frequency-specific attack strategies tailored to their respective contributions to watermark robustness and perceptual quality. In the next stage, the Frequency-domain Residual Diffusion Attack Module (FRDAM) separately models the residual distributions between the preliminarily attacked outputs and the corresponding watermark-free references during training. Rather than reconstructing the entire image, FRDAM selectively refines frequency-domain residuals, directing the diffusion process toward the remaining watermark related discrepancies while minimizing modifications to image content. Extensive experiments on CelebA and ImageNet across four representative watermarking schemes demonstrate that FDDWAN achieves a more favorable trade-off between watermark removal effectiveness and visual fidelity than conventional and learning-based attack methods.

水印攻击扩散模型小波分析图像保真

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。