用密集伪随机码扩散水印,提升抗删除能力
SpreadMark: Robust Image Watermarking via Spread-Spectrum Embedding

- 将每个水印比特扩展为全图分布的伪随机码
- 在九种攻击下仍保持高检测率,尤其抗潜空间稀疏化
- 适合需要强鲁棒性的深度伪造溯源场景
不可见图像水印广泛用于深度伪造检测与来源追踪,需同时抵御偶然失真和故意移除。本文重新审视经典扩频嵌入原理,在现代神经后处理水印架构中实现改进。现有编解码方案中每个消息比特仅占据图像小部分区域,导致脆弱性;而SpreadMark将每个比特以密集伪随机码形式分布于整张图像,并通过学习到的掩蔽覆盖芯片表示进行匹配滤波恢复,配备并行卷积解码路径与稀疏感知训练。条件芯片空间分析表明,在码字无关扰动模型下,密集扩散可显著提高破坏匹配滤波所需的干扰预算。在COCO与DIV2K数据集上对九种方法的评估显示,SpreadMark是唯一在再生与潜在空间稀疏化设置下均保持高检测率的方法,且具备与现有方法相当的JPEG及加性噪声鲁棒性。水印保持不可察觉,两数据集上均维持高感知质量。
原文摘要 · Abstract (English)
Invisible image watermarks are increasingly used for deepfake detection and provenance tracking, where they must survive not only incidental distortions but also deliberate removal. We revisit spread-spectrum embedding, a classical watermarking principle, inside a modern neural post-hoc watermarking architecture. Our starting point is a measurement: in existing encoder-decoder schemes each message bit occupies only a small fraction of the image, a shared contributing factor to their fragility, since removal then need only disturb the region a bit occupies. SpreadMark instead spreads each bit as a dense pseudo-random codeword over the whole image and recovers it by matched-filtering a learned cover-suppressed chip representation, with a parallel convolutional decoding path and sparsification-aware training. A conditional chip-space analysis shows that, under a codeword-independent perturbation model, dense spreading increases the budget required to disrupt matched-filter recovery. Evaluated on COCO and DIV2K against nine schemes, SpreadMark is the only evaluated method retaining high detection under both the regeneration and the latent-space sparsification settings we test, with competitive JPEG and additive-noise robustness. It keeps the embedded watermark imperceptible, maintaining high perceptual quality on both COCO and DIV2K.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。