arXiv:2607.27811cs.CV2026-07

用视觉语义和频域约束提升隐写攻击效果,兼顾去水印与图像质量。

SPFM-Net: Semantic-Prior-Guided Frequency-Constrained Mamba for Invisible Watermark Attack

论文配图:SPFM-Net: Semantic-Prior-Guided Frequency-Constrained Mamba for Invisible Watermark Attack
图 1 · 摘自论文原文
  • 结合语义先验与频域约束,用Mamba捕捉全局水印依赖关系。
  • 在多个水印方案上实现高效去水印,同时保持图像感知质量。
  • 适合研究隐写攻击、图像安全与鲁棒性防御的学者使用。

现有隐写攻击多依赖预定义信号处理操作或局部恢复网络,难以捕捉全局分布水印信号的长程依赖,导致去水印效果与视觉保真度之间权衡不佳。本文提出SPFM-Net,一种基于语义先验与频域约束的Mamba框架,用于隐写攻击。首先通过高比例掩码破坏水印的空间连贯性,再利用部分微调的预训练掩码自编码器从稀疏观测中重建语义一致图像并抑制水印信息。随后,多尺度残差频域特征交互模块在多感受野下聚合水印相关残差特征,并自适应抑制无关区域响应。为进一步建模全局水印信号的长程依赖,引入轻量级基于Mamba的全局状态空间特征建模(GSFM)单元,分离水印特征并抑制残留痕迹。此外,采用多层次目标函数联合施加空间、频率与边缘域约束,实现有效水印抑制的同时保持感知质量。在典型空间域、变换域、正交矩基及深度学习水印方案上的大量实验表明,SPFM-Net在去水印有效性与感知保真度间取得良好平衡。

原文摘要 · Abstract (English)

Existing watermark attacks typically rely on predefined signal-processing operations or locally constrained restoration networks, making it difficult to capture the long-range dependencies of globally distributed watermark signals and resulting in an unfavorable trade-off between removal effectiveness and visual fidelity. In this paper, we propose SPFM-Net, a semantic-prior-guided and frequency-constrained Mamba framework for invisible watermark attack. SPFM-Net first employs high-ratio masking to disrupt the spatial coherence of invisible watermark signals, and then utilizes a partially fine-tuned pretrained Masked Autoencoder to reconstruct semantically consistent image from sparse observations while suppressing watermark-related information. A Multi-scale Residual Frequency Feature Interaction module subsequently aggregates watermark-related residual features across multiple receptive fields, while adaptively suppressing responses from watermark-irrelevant regions. To further capture the long-range dependencies of globally distributed watermark signals, a lightweight Mamba-based Global State-space Feature Modeling (GSFM) unit is introduced to separate watermark-related features from natural image content and suppress the remaining watermark traces. In addition, SPFM-Net is optimized using a multi-level objective that jointly imposes spatial-, frequency-, and edge-domain constraints, enabling effective watermark suppression while preserving perceptual quality. Extensive experiments on representative spatial-domain, transform-domain, orthogonal moment-based, and deep learning-based watermarking schemes demonstrate that SPFM-Net achieves a favorable trade-off between watermark attack effectiveness and perceptual fidelity.

隐写攻击Mamba图像安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。