arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.32241cs.CRcs.CV

神经图像水印中的残差可迁移性

Residual Transferability in Neural Image Watermarking

Ziping Dong, Qi Li, Xinchao Wang

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出残差可迁移性(RT)指标量化神经水印的伪造漏洞,发现架构设计而非训练差异是关键,并识别两种抑制机制,同时提出即插即用的CoverLock策略以提升现有系统的抗伪造性。

中文摘要 AI 辅助

神经图像水印可以通过从已发布的图像中提取含水印的残差并将其迁移到无关内容上来进行伪造。虽然先前的工作已经证明了这一漏洞,但究竟是什么使得这些残差具有可迁移性仍然知之甚少。我们使用\textbf{残差可迁移性(RT)}这一指标来形式化该漏洞,该指标量化了水印证据在跨无关图像迁移后仍可被解码的程度。通过比较分析和受控干预,我们发现常见的训练侧变化并不能解释不同水印系统之间RT的巨大差异;相反,架构设计起着核心作用。通过对比高RT和低RT系统,并通过受控干预验证其架构差异,我们识别出两种增强水印证据对封面图像依赖性的机制,从而抑制残差可迁移性。这些发现为开发更具抗伪造性的水印架构提供了具体的设计指导。作为补充,对于架构重新设计不可行的现有水印系统,我们引入了\textbf{CoverLock},一种即插即用策略,无需架构重新设计即可增强此类图像依赖性。在表现出高残差可迁移性的代表性水印系统中,CoverLock在安全性与鲁棒性之间取得了比传统手工防御和基于学习的分类器防御都更优的权衡。

英文摘要

Neural image watermarks can be forged by extracting watermark-bearing residuals from released images and transferring them to unrelated content. While prior work has demonstrated this vulnerability, what makes these residuals transferable remains poorly understood. We formalize this vulnerability with \textbf{residual transferability (RT)}, a metric that quantifies how well watermark evidence remains decodable after transfer across unrelated images. Through comparative analyses and controlled interventions, we find that common training-side variations do not account for the large RT differences across watermarking systems; instead, architectural design plays a central role. By contrasting high- and low-RT systems and validating their architectural differences through controlled interventions, we identify two mechanisms that strengthen the dependence of watermark evidence on the cover image, thereby suppressing the residual transferability. These findings provide concrete design guidance for developing more forgery-resistant watermarking architectures. Complementarily, for existing watermarking systems where architectural redesign is impractical, we introduce \textbf{CoverLock}, a plug-and-play strategy for existing watermarking systems that strengthens such image dependence without architectural redesign. Across representative watermarking systems exhibiting high residual transferability, CoverLock achieves a more favorable security--robustness trade-off than both traditional handcrafted defenses and learned classifier-based defenses.

发表机构

  • National University of Singapore(新加坡国立大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑