发表机构
Institute of Communication Systems, Faculty of Electronics, Military University of Technology(军事科技大学电子学院通信系统研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文分析深度图像水印鲁棒性的三类限制机制,发现限制源于失真类别而非容量,提出可验证泛化性的评估协议。
AI 中文摘要
鲁棒性仍然是深度图像水印领域的主要开放问题,且随着载荷(payload)的增长,其限制因素愈发明显。本文探讨容量本身是否为限制因素,或仅使其他限制因素显现,并分两部分作答:第一部分梳理水印必须抵御的失真类型及对应的抵抗策略,分别按载荷容量(针对失真)、可微性(针对策略)的维度排序;第二部分识别并量化三类限制鲁棒性的机制,针对将载荷映射至空间块网格、且提取器与冻结嵌入器分开训练的方案,三类机制为:载荷网格的失步、编解码器诱导失真对训练的抵抗、可用嵌入强度窗口的收窄。本文测量了64至16384位的载荷,远超上述策略适用范围;针对编解码器训练提取阶段不仅无效,反而会损害训练所用操作点的读取性能。研究得出,限制因素属于失真类别而非容量本身,且通过进一步训练提取阶段无法消除任何限制,因为三类机制均产生于提取阶段之前;本文还提出了可验证泛化性的评估协议,结论属于一类设计的属性而非某一实现。
英文摘要
Robustness remains the principal open problem in deep image watermarking, and what limits it becomes sharper as payload grows. This paper asks whether capacity is itself the limit or only makes other limits visible, and answers in two parts. The first organizes the distortions a watermark must survive and the strategies developed to resist them, ordering each by the axis that governs it: payload capacity for the distortions, differentiability for the strategies. The second identifies and measures three mechanisms that limit robustness in schemes mapping the payload onto a spatial block grid with extraction trained separately from a frozen embedder: desynchronization of the payload grid, the resistance of codec-induced distortion to training, and the narrowing of the usable embedding-strength window. Payloads from 64 to 16384 bits are measured, well beyond the range those strategies address. Training the extraction stage against a codec proves not merely ineffective but harmful, degrading the reading at the operating points used in training. The limits follow the class of distortion rather than capacity itself, and none is removed by further training on the extraction side, because all three arise before extraction. An evaluation protocol making claims of generalization verifiable is also contributed. The conclusions are properties of a class of designs rather than of one implementation.
CommentsSubmitted to IEEE Access