AI 中文总结
该研究针对现有水印去除方法的权衡缺陷,提出FDDWAN框架,经实验验证其在水印去除与视觉保真度间的表现优于传统及学习型攻击方法。
AI 中文摘要
现有的不可见水印去除方法常难以准确捕捉含水印特征,导致水印抑制与感知保真度之间存在不利权衡。本文提出频率解耦扩散水印攻击网络(FDDWAN),这是一种由粗到精的框架,通过小波域分解与残差扩散细化实现水印去除。初始阶段,基于小波的频域初步攻击模块(WFPAM)将含水印图像分解为低频和高频子带,针对其对水印鲁棒性和感知质量的不同贡献应用频率特定攻击策略。下一阶段,频域残差扩散攻击模块(FRDAM)在训练期间分别建模初步攻击输出与对应无水印参考之间的残差分布。FRDAM不重建整个图像,而是选择性细化频域残差,引导扩散过程聚焦于剩余水印相关差异,同时最小化对图像内容的修改。在CelebA和ImageNet数据集上针对四种代表性水印方案开展的大量实验表明,FDDWAN相比传统方法和基于学习的攻击方法,在水印去除有效性与视觉保真度之间实现了更优权衡。
英文摘要
Existing invisible watermark removal methods often struggle to accurately capture the watermark-bearing features, leading to an unfavorable trade-off between watermark suppression and perceptual fidelity. In this paper, we propose the Frequency-Decoupled Diffusion Watermark Attack Network (FDDWAN), a coarse-to-fine framework that performs watermark removal through wavelet-domain decomposition and residual diffusion refinement. In the initial stage, the Wavelet-based Frequency-domain Preliminary Attack Module (WFPAM) decomposes the watermarked image into low- and high-frequency subbands and applies frequency-specific attack strategies tailored to their respective contributions to watermark robustness and perceptual quality. In the next stage, the Frequency-domain Residual Diffusion Attack Module (FRDAM) separately models the residual distributions between the preliminarily attacked outputs and the corresponding watermark-free references during training. Rather than reconstructing the entire image, FRDAM selectively refines frequency-domain residuals, directing the diffusion process toward the remaining watermark related discrepancies while minimizing modifications to image content. Extensive experiments on CelebA and ImageNet across four representative watermarking schemes demonstrate that FDDWAN achieves a more favorable trade-off between watermark removal effectiveness and visual fidelity than conventional and learning-based attack methods.