发表机构
Korea University(高丽大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出语义水印框架CLIP-VAE,结合β-VAE与通道感知训练,实现恶意图像篡改检测及语义方向识别,优于二进制哈希基线。
AI 中文摘要
高保真生成式编辑模型的普及使得在保持视觉合理性的同时,将暴力或色情内容注入原本普通的图像成为可能,这对公共话语和弱势群体产生了具体后果。我们提出了一种鲁棒的语义水印框架,将水印重新定义为可恢复的语义参考,而非不透明的标识符。我们的框架将基于β-VAE的二进制水印(CLIP-VAE)与显式的通道感知训练相结合——在训练期间注入随机比特翻转噪声,使解码器学会在噪声水印信道下优雅地退化。作为下游应用,轻量级模块SDA-Net利用恢复的语义嵌入,不仅揭示图像是否被篡改,还揭示其被篡改的语义方向。在与代表性二进制哈希基线(SimHash、ITQ、HashNet及其鲁棒MLP变体)的5路比较中,CLIP-VAE在现实InstructPix2Pix比特错误率下,实现了与原始CLIP嵌入的最高重建余弦相似度,并独特地支持漂移方向检测——这是对现有内容审核流程的法证补充。
英文摘要
The proliferation of high-fidelity generative editing models has made it possible to inject violent or sexual content into otherwise ordinary images while preserving visual plausibility, with concrete consequences for public discourse and vulnerable populations. We propose a robust semantic watermarking framework that reframes the watermark as a recoverable semantic reference rather than an opaque identifier. Our framework combines a $β$-VAE-based binary watermark (CLIP-VAE) with explicit channel-aware training---random bit-flip noise is injected during training so that the decoder learns graceful degradation under the noisy watermarking channel. As a downstream application, a lightweight module SDA-Net uses the recovered semantic embedding to expose not only whether but in which semantic direction an image has been altered. In a 5-way comparison against representative binary hashing baselines (SimHash, ITQ, HashNet, and their robust-MLP variants), CLIP-VAE achieves the highest reconstruction cosine similarity to the original CLIP embedding under realistic InstructPix2Pix bit-error rates, and uniquely supports direction-of-drift detection---a forensic complement to existing content-moderation pipelines.