发表机构
University of New South Wales; National University of Singapore(新南威尔士大学; 新加坡国立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出SpreadMark,通过将每个消息比特以密集伪随机码字分布于全图像的扩频嵌入方式,提升了图像水印的鲁棒性,在多数据集测试中表现优于9种方案,兼具高检测性能与不可感知性。
AI 中文摘要
不可见图像水印正越来越多地用于深度伪造检测和来源追踪,它们不仅必须经受住偶然失真,还必须抵御刻意移除。我们在现代神经事后水印架构中重新审视了经典水印原理——扩频嵌入。我们的出发点是一项观察:在现有的编解码器方案中,每个消息比特仅占据图像的一小部分,这是其脆弱性的共同促成因素,因为移除操作只需干扰该比特所占区域即可。SpreadMark则相反,将每个比特作为密集伪随机码字分布在整个图像上,并通过匹配滤波恢复,该滤波基于学习到的覆盖抑制码片表示,配备并行卷积解码路径和感知稀疏性的训练。条件码片空间分析表明,在码字独立扰动模型下,密集分布增加了破坏匹配滤波恢复所需的预算。在COCO和DIV2K数据集上针对9种方案进行评估,SpreadMark是唯一在我们测试的再生和隐空间稀疏化设置下均保持高检测性能的评估方法,同时具备有竞争力的JPEG和加性噪声鲁棒性,且保持嵌入水印的不可感知性,在COCO和DIV2K上均维持高感知质量。
英文摘要
Invisible image watermarks are increasingly used for deepfake detection and provenance tracking, where they must survive not only incidental distortions but also deliberate removal. We revisit spread-spectrum embedding, a classical watermarking principle, inside a modern neural post-hoc watermarking architecture. Our starting point is a measurement: in existing encoder-decoder schemes each message bit occupies only a small fraction of the image, a shared contributing factor to their fragility, since removal then need only disturb the region a bit occupies. SpreadMark instead spreads each bit as a dense pseudo-random codeword over the whole image and recovers it by matched-filtering a learned cover-suppressed chip representation, with a parallel convolutional decoding path and sparsification-aware training. A conditional chip-space analysis shows that, under a codeword-independent perturbation model, dense spreading increases the budget required to disrupt matched-filter recovery. Evaluated on COCO and DIV2K against nine schemes, SpreadMark is the only evaluated method retaining high detection under both the regeneration and the latent-space sparsification settings we test, with competitive JPEG and additive-noise robustness. It keeps the embedded watermark imperceptible, maintaining high perceptual quality on both COCO and DIV2K.
Comments12 pages, 6 figures