提出一种新方法,可在图像完全重生成后仍精准定位篡改区域。
APT: Anchor-aligned Perturbations for Tamper Localization in Fully Regenerated Images

- 在潜在空间中嵌入向量对齐信号,利用特征方向差异定位篡改
- 在COCO数据集上实现0.92的完全再生检测交并比,远超现有方法
- 适用于未知篡改类型,对扩散模型修复场景具有强实用性
主动篡改定位在图像分发前嵌入不可察觉的信号,实现像素级篡改检测。现有方法假设拼接(SP)场景,即合成区域叠加于原背景,嵌入信号保持完整。然而真实世界中的扩散模型修复处于完全重生成(FR)场景,整个图像经历去噪,破坏背景信号,使现有框架失效。本文提出APT,一种半脆弱的潜在空间扰动,在潜在空间中嵌入密集的、向量级的定位信号。通过将每个空间特征向量对齐至固定锚定方向,利用修复后合成前景与锚定对齐背景特征间的对齐差异进行篡改定位。所提硬负样本挖掘损失和噪声扰动分支进一步强化了均匀对齐。在COCO数据集上的实验表明,APT实现了0.92的FR IoU,显著优于最强基线(WAM,0.84),而现有方法性能退化至接近随机(AUC 0.5),确立了APT作为跨篡改类型通用的实用取证框架。
原文摘要 · Abstract (English)
Proactive tamper localization embeds an imperceptible signal into an image prior to distribution, enabling pixel-level manipulation detection. Existing methods assume a spliced (SP) setting, where synthesized regions are composited onto the original background, leaving embedded signals intact. However, real-world diffusion-based inpainting operates in a fully regenerated (FR) setting, where the entire image undergoes denoising, disrupting background signals and rendering existing frameworks ineffective. We propose APT, a semi-fragile latent-space perturbation that embeds a dense, vector-wise localization signal. By aligning each spatial feature vector toward a fixed anchor direction, APT localizes tampering via the alignment disparity between synthesized foreground and anchor-aligned background features after inpainting. The proposed hard negative mining loss and noisy perturbation branch further enforce uniform alignment. Experiments on COCO demonstrate that APT achieves an FR IoU of 0.92, outperforming the strongest baseline (WAM, 0.84), while existing methods collapse to near-random performance (AUC 0.5), establishing APT as a practical forensic framework generalizable across tampering types unknown at test time.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。