水印藏于何处?用于不可见水印去除的推拉解耦方法
Where Does the Watermark Hide? Push-Pull Disentanglement for Invisible Watermark Removal
浏览论文内容
中文总结 AI 辅助
针对从配对干净与水印图像学习的攻击,提出推拉解耦方法,通过结构潜变量和辅助残差潜变量实现单图像推理下的水印去除,实验显示辅助输入对解码器有依赖,但理论解释为事后分析而非验证结果。
中文摘要 AI 辅助
固定的图像失真无法防御一种攻击者,该攻击者从配对的干净图像和水印图像中学习。我们研究这种配对训练威胁,并采用单图像推理:部署时既不使用干净参考图像,也不使用水印密钥、载荷或解码器。一个编码器将每幅图像映射为结构潜变量$g$和辅助残差潜变量$u$。推监督从$D(g_w,u_w)$重建水印图像。拉监督训练零辅助输出$D(A_g(g_w;k),0)$使其接近配对的干净图像。在$k=1.10,u=0$时,四种方法的平均比特错误率(BER)为$0.3958$,峰值信噪比(PSNR)为$31.07$ dB,结构相似性指数(SSIM)为$0.9554$。将$u$从$0$恢复到$0.15$,平均BER从$0.3893$降至$0.3357$,而PSNR从$30.99$降至$28.23$ dB。该干预支持在所评估的设置中解码器对辅助输入的依赖。随附的理论是对该行为的一种条件性、事后解释,而非经过实验验证的信息重定位结果。
英文摘要
Fixed image distortions do not cover an attacker that learns from paired clean and watermarked images. We study this paired-training threat with single-image inference: deployment uses neither the clean reference nor the watermark key, payload, or decoder. An encoder maps each image to a structural latent $g$ and an auxiliary residual latent $u$. Push supervision reconstructs the watermarked image from $D(g_w,u_w)$. Pull supervision trains the zero-auxiliary output $D(A_g(g_w;k),0)$ toward the paired clean image. At $k=1.10,u=0$, the four-method sweep gives an average BER of $0.3958$, PSNR of $31.07$ dB, and SSIM of $0.9554$. Restoring $u$ from $0$ to $0.15$ moves average BER from $0.3893$ to $0.3357$, while PSNR falls from $30.99$ to $28.23$ dB. The intervention supports decoder dependence on the auxiliary input in the evaluated setting. The accompanying theory is a conditional, post-hoc account of this behavior rather than an experimentally verified information-relocation result.