Invisible Watermarks: Attacks and Robustness

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Hwang, Dongjun, Woo, Sungwon, Gao, Tom, Luo, Raymond, Baek, Sunghwan
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866917870875705344
author Hwang, Dongjun
Woo, Sungwon
Gao, Tom
Luo, Raymond
Baek, Sunghwan
author_facet Hwang, Dongjun
Woo, Sungwon
Gao, Tom
Luo, Raymond
Baek, Sunghwan
contents As Generative AI continues to become more accessible, the case for robust detection of generated images in order to combat misinformation is stronger than ever. Invisible watermarking methods act as identifiers of generated content, embedding image- and latent-space messages that are robust to many forms of perturbations. The majority of current research investigates full-image attacks against images with a single watermarking method applied. We introduce novel improvements to watermarking robustness as well as minimizing degradation on image quality during attack. Firstly, we examine the application of both image-space and latent-space watermarking methods on a single image, where we propose a custom watermark remover network which preserves one of the watermarking modalities while completely removing the other during decoding. Then, we investigate localized blurring attacks (LBA) on watermarked images based on the GradCAM heatmap acquired from the watermark decoder in order to reduce the amount of degradation to the target image. Our evaluation suggests that 1) implementing the watermark remover model to preserve one of the watermark modalities when decoding the other modality slightly improves on the baseline performance, and that 2) LBA degrades the image significantly less compared to uniform blurring of the entire image. Code is available at: https://github.com/tomputer-g/IDL_WAR
format Preprint
id arxiv_https___arxiv_org_abs_2412_12511
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Invisible Watermarks: Attacks and Robustness
Hwang, Dongjun
Woo, Sungwon
Gao, Tom
Luo, Raymond
Baek, Sunghwan
Computer Vision and Pattern Recognition
As Generative AI continues to become more accessible, the case for robust detection of generated images in order to combat misinformation is stronger than ever. Invisible watermarking methods act as identifiers of generated content, embedding image- and latent-space messages that are robust to many forms of perturbations. The majority of current research investigates full-image attacks against images with a single watermarking method applied. We introduce novel improvements to watermarking robustness as well as minimizing degradation on image quality during attack. Firstly, we examine the application of both image-space and latent-space watermarking methods on a single image, where we propose a custom watermark remover network which preserves one of the watermarking modalities while completely removing the other during decoding. Then, we investigate localized blurring attacks (LBA) on watermarked images based on the GradCAM heatmap acquired from the watermark decoder in order to reduce the amount of degradation to the target image. Our evaluation suggests that 1) implementing the watermark remover model to preserve one of the watermark modalities when decoding the other modality slightly improves on the baseline performance, and that 2) LBA degrades the image significantly less compared to uniform blurring of the entire image. Code is available at: https://github.com/tomputer-g/IDL_WAR
title Invisible Watermarks: Attacks and Robustness
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2412.12511