解耦与丢弃:通过重建灰度残差分解实现鲁棒的通用图像水印去除
Disentangle and Drop: Robust Universal Removal of Image Watermarks via Reconstructive Grayscale Residual Decomposition
浏览论文内容
中文总结 AI 辅助
本文提出DnD方法,通过将带水印图像分解为语义灰度载体和残差分支并丢弃残差,实现与水印方法无关的通用去除,在七个水印家族上验证了高保真去除效果,主张在表示层面评估水印鲁棒性。
中文摘要 AI 辅助
不可见图像水印通常针对良性后处理操作(如压缩、调整大小、模糊和颜色变化)进行评估。这些测试忽略了一种不同的威胁:一种学习型去除器,它在保留语义图像内容的同时丢弃携带载荷的残差证据。我们提出了“解耦与丢弃”(DnD),这是一种与水印方法无关的攻击,将水印去除视为表示路由问题。DnD将带水印的图像分解为语义灰度载体和辅助残差分支,然后抑制残差分支以减少水印证据。该模型通过潜在频谱扰动和低强度扩散暴露进行训练,使得丢弃操作在自适应重建下保持稳定。在七个代表性水印家族上的实验表明,一个共享的操作设置即可实现具有高视觉保真度的竞争性去除效果。操作扫描和消融研究将可用的攻击与损害图像的操作区分开来:更强的噪声或扩散可以通过损害图像来提高去除分数,而实际可行的机制在于丢弃残差潜在变量。这些结果主张在表示层面评估水印对学习型去除的鲁棒性,而不仅仅针对传统图像编辑。
英文摘要
Invisible image watermarks are commonly evaluated against benign postprocessing operations such as compression, resizing, blur, and color changes. These tests leave out a different threat: a learned remover that preserves semantic image content while discarding residual evidence that carries the payload. We propose Disentangle and Drop (DnD), an attack that is agnostic to the watermark method and treats watermark removal as a representation routing problem. DnD decomposes a watermarked image into a semantic grayscale carrier and an auxiliary residual branch, and then suppresses the residual branch to reduce watermark evidence. The model is trained with latent spectral perturbations and low-strength diffusion exposure so that the drop operation remains stable under adaptive reconstruction. Experiments on seven representative watermark families show that one shared operating setting gives competitive removal with high visual fidelity. Operating scans and ablations separate usable attacks from image-damaging settings: stronger noise or diffusion can raise removal scores by damaging the image, while the practical regime comes from dropping the residual latent. These results argue for evaluating watermark robustness against learned removal at the representation level, not only against conventional image edits.