RemTraceNet:不可见水印攻击的少样本取证检测
RemTraceNet: Few-Shot Forensic Detection of Invisible Watermark Attacks
浏览论文内容
中文总结 AI 辅助
针对水印去除的取证隐蔽性问题,提出少样本取证网络RemTraceNet,融合多种残差与频域证据,在23个流程上优于基线10.8-15.7个百分点,证明去除痕迹可学习。
中文摘要 AI 辅助
去除不可见水印与隐藏取证证据是两个不同的目标:成功破坏嵌入的水印并不意味着去除过程在取证上是不可检测的。当验证失败时,去除痕迹可以为来源和所有权验证提供补充证据,而痕迹的缺失则使失败原因变得模糊不清。现有方法通常通过水印抑制和感知质量进行评估,而取证隐蔽性很少被考虑。因此,我们研究针对水印攻击的少样本取证:对于每个已知流程,专家模型可以将其输出与配对的干净图像和未受攻击的水印对照图像区分开来。分别进行攻击与干净图像、攻击与水印图像的评估,以避免水印存在性捷径。对于事后方案和生成器集成方案,分别使用图像对齐和提示匹配的对照图像。在本工作中,我们引入了RemTraceNet,它在原生分辨率下融合了约束残差、局部关系、FFT/Haar统计和块DCT证据。在23个去除流程和10种水印配置下,我们评估了原生256×256和512×512的输入。每个流程使用100张受攻击的训练图像,三随机种子下的TPR@1%FPR(在攻击和水印配置上取宏平均)在不同分辨率和对照类型下范围为82.75%至88.17%。在相同标签和协议条件下,RemTraceNet比重新训练的SRNet、ZhuNet和SiaStegNet基线高出10.80至15.68个百分点。大量实验结果表明,擦除水印和擦除其去除证据是不同的挑战,且去除痕迹在有限监督下仍然可学习。
英文摘要
Removing an invisible watermark and concealing the forensic evidence are distinct objectives: successfully disrupting the embedded watermark does not imply that the removal process is forensically undetectable. When verification fails, removal traces can provide complementary evidence for provenance and ownership verification, whereas their absence leaves the cause of the failure ambiguous. Existing methods are typically evaluated by watermark suppression and perceptual quality, while forensic stealth is rarely considered. We therefore study watermark-attack-specific few-shot forensics: for each known pipeline, a specialist can separate its outputs from paired clean and unattacked watermarked controls. Separate Attack-vs-Clean and Attack-vs-Watermarked evaluations prevent watermark-presence shortcuts. Image-aligned and prompt-matched controls are used for post-hoc and generator-integrated schemes, respectively. In this work, we introduce RemTraceNet, which fuses constrained residuals, local relations, FFT/Haar statistics, and block-DCT evidence at native resolution. Across 23 removal pipelines and 10 watermark configurations, we evaluate native 256 x 256 and 512 x 512 inputs. With 100 attacked training images per pipeline, the three-seed TPR@1%FPR, macro-averaged over attacks and watermark configurations, ranges from 82.75% to 88.17% across resolutions and control types. Under the condition of same labels and protocol, RemTraceNet outperforms retrained SRNet, ZhuNet, and SiaStegNet baselines by 10.80--15.68 percentage points. Extensive experimental results show that erasing a watermark and erasing evidence of its removal are distinct challenges, and that removal traces remain learnable under limited supervision.