WARP:不可见图像水印的统一基准——鲁棒性与对抗攻击防护
WARP: A Unified Benchmark for Invisible Image Watermarking -- Robustness and Protection Against Attacks
浏览论文内容
中文总结 AI 辅助
本文提出WARP,一个统一基准,整合32种水印方法和34种攻击,系统评估不可见水印的鲁棒性,识别最鲁棒方法及攻击弱点,并开源代码。
中文摘要 AI 辅助
数字图像水印在媒体环境中日益关键,因为新兴法规和行业实践要求对AI生成内容进行标记,并确保来源可追溯,以防止篡改或滥用。近期不可见水印方法的进展凸显了更新现有基准测试实践以反映当前技术和评估标准的必要性。为此,我们引入WARP——一个用于评估不可见水印鲁棒性的统一框架和基准。WARP整合了32种近期经典、深度和生成式水印方法,以及34种不同的擦除技术,涵盖从传统失真到更复杂的对抗、净化和重嵌入攻击。它提供了标准化、可复现且易于扩展的协议,用于评估感知质量、水印可读性和攻击韧性。利用WARP,我们广泛评估了当前的不可见水印技术,收集了该领域最大的鲁棒性基准。结果识别了在失真和对抗条件下最鲁棒的方法,并揭示了水印方法与对其最有效的攻击策略之间的一致关系。我们的实验还强调,一些所考虑的水印方法即使对标准失真具有鲁棒性,也极易受到重嵌入攻击。代码可在该https URL获取。
英文摘要
Digital image watermarking is increasingly critical in media contexts, as emerging regulations and industry practices require marking AI-generated content and ensuring traceable sources to prevent manipulation or misuse. Recent advances in invisible watermarking methods highlight the need to update existing benchmarking practices to reflect current techniques and evaluation criteria. We address this by introducing WARP -- a unified framework and benchmark for evaluating the robustness of invisible watermarks. WARP incorporates 32 recent classical, deep, and generative watermarking methods, as well as 34 different erasing techniques, ranging from traditional distortions to more sophisticated adversarial, purification, and re-embedding attacks. It provides standardized, reproducible, and easily scalable protocols for evaluating perceptual quality, watermark readability, and attack resilience. Using WARP, we extensively evaluate current invisible watermarking techniques, collecting the largest robustness benchmark in the field. Results identify the most robust approaches under both distortion and adversarial conditions, and reveal consistent relationships between watermarking methods and the attack strategies most effective against them. Our experiments also highlight that some of the watermarking methods considered are highly vulnerable to reembedding, even if they are robust to standard distortions. The code is made available at https://github.com/ispras/wibe.
发表机构
- MSU Institute for Artificial Intelligence(莫斯科国立大学人工智能研究所)
- Trusted AI Research Center RAS(俄罗斯科学院可信人工智能研究中心)
机构由 AI 辅助整理,请以论文原文为准。