arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

优化与保障现代图像水印信道

Optimizing and Securing the Modern Watermarking Channel for Images

Enoal Gesny, Eva Giboulot

arXiv 2609.34744首次发表:更新:

发表机构

Inria(法国国家信息与自动化研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对现代事后图像水印缺乏理论保障与安全性问题,提出统计信道模型并揭示其容量与密钥缺陷,进而设计SNW系统,以接近香农容量且强安全性的优势超越现有基线。

AI 中文摘要

为遵守近期要求可追溯生成内容的规定,现代水印技术已采用多比特事后水印方案。这些现代设计基于由深度神经网络实现的编码器-解码器对。这些模型通常被视为端到端训练的纯黑盒,水印信道的噪声通过应用于水印图像的固定几何与数值变换集合来建模。我们认为这种纯经验方法导致了未经质疑的设计缺陷和缺乏理论性能保证。本工作提出一个基于编码器/解码器对输出的统计分析的一般性理论模型,用于现代事后水印方案。我们证明这些深度神经网络隐式定义了一个建模为并行AWGN信道的水印信道,消息使用BPSK调制传输。这强制使用二元字母表,极大限制了这些水印系统的容量。另一个致命缺陷是缺乏密钥,使其本质上不安全。我们通过将水印安全性的概念与在给定解码器输出的统计模型下估计密钥的可能性联系起来,为事后方案精确定义了这一概念。综合理论分析的结果,我们引入了SNW:一种新颖的事后水印系统,在容量方面显著优于现有最先进基线,同时提供强大的安全保证。值得注意的是,它不依赖于固定码本或二元字母表,通过使用容量接近的纠错码,使其速率接近香农容量。

英文摘要

To comply with recent regulations requiring traceable generated content, modern watermarking has adopted multi-bit post-hoc watermarking schemes. These modern designs rest on an encoder-decoder pair implemented as deep neural networks. These models are usually treated as pure black-boxes trained end-to-end, with the noise of the watermarking channel modeled through a fixed set of geometric and valuemetric transforms applied to watermarked images. We argue that this purely empirical approach leads to unquestioned design flaws and a lack of theoretical performance guarantees. This work proposes a general theoretical model of modern post-hoc watermarking schemes grounded in a statistical analysis of the outputs of the encoder/decoder pair. We show that these deep neural networks implicitly define a watermarking channel modeled as parallel AWGN channels, with messages transmitted using BPSK modulation. This imposes a binary alphabet, greatly limiting the capacity of these watermarking systems. Another fatal flaw is their lack of a secret key, making them intrinsically insecure. We make this notion of watermarking security precise for post-hoc schemes by linking it to the possibility of estimating the secret key under a given statistical model of the decoder's output. By putting together the results from this theoretical analysis, we introduce SNW: a novel post-hoc watermarking system that significantly outperforms existing state-of-the-art baselines in terms of capacity while also providing strong security guarantees. Notably, it does not depend on a fixed codebook or binary alphabet, allowing it to reach a rate close to Shannon capacity through the use of capacity-achieving error-correcting codes.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑