Adversarial Shallow Watermarking

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Guobiao, Tan, Lei, Xue, Yuliang, Liu, Gaozhi, Qian, Zhenxing, Li, Sheng, Zhang, Xinpeng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910920554315776
author Li, Guobiao
Tan, Lei
Xue, Yuliang
Liu, Gaozhi
Qian, Zhenxing
Li, Sheng
Zhang, Xinpeng
author_facet Li, Guobiao
Tan, Lei
Xue, Yuliang
Liu, Gaozhi
Qian, Zhenxing
Li, Sheng
Zhang, Xinpeng
contents Recent advances in digital watermarking make use of deep neural networks for message embedding and extraction. They typically follow the ``encoder-noise layer-decoder''-based architecture. By deliberately establishing a differentiable noise layer to simulate the distortion of the watermarked signal, they jointly train the deep encoder and decoder to fit the noise layer to guarantee robustness. As a result, they are usually weak against unknown distortions that are not used in their training pipeline. In this paper, we propose a novel watermarking framework to resist unknown distortions, namely Adversarial Shallow Watermarking (ASW). ASW utilizes only a shallow decoder that is randomly parameterized and designed to be insensitive to distortions for watermarking extraction. During the watermark embedding, ASW freezes the shallow decoder and adversarially optimizes a host image until its updated version (i.e., the watermarked image) stably triggers the shallow decoder to output the watermark message. During the watermark extraction, it accurately recovers the message from the watermarked image by leveraging the insensitive nature of the shallow decoder against arbitrary distortions. Our ASW is training-free, encoder-free, and noise layer-free. Experiments indicate that the watermarked images created by ASW have strong robustness against various unknown distortions. Compared to the existing ``encoder-noise layer-decoder'' approaches, ASW achieves comparable results on known distortions and better robustness on unknown distortions.
format Preprint
id arxiv_https___arxiv_org_abs_2504_19529
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarial Shallow Watermarking
Li, Guobiao
Tan, Lei
Xue, Yuliang
Liu, Gaozhi
Qian, Zhenxing
Li, Sheng
Zhang, Xinpeng
Computer Vision and Pattern Recognition
Multimedia
Recent advances in digital watermarking make use of deep neural networks for message embedding and extraction. They typically follow the ``encoder-noise layer-decoder''-based architecture. By deliberately establishing a differentiable noise layer to simulate the distortion of the watermarked signal, they jointly train the deep encoder and decoder to fit the noise layer to guarantee robustness. As a result, they are usually weak against unknown distortions that are not used in their training pipeline. In this paper, we propose a novel watermarking framework to resist unknown distortions, namely Adversarial Shallow Watermarking (ASW). ASW utilizes only a shallow decoder that is randomly parameterized and designed to be insensitive to distortions for watermarking extraction. During the watermark embedding, ASW freezes the shallow decoder and adversarially optimizes a host image until its updated version (i.e., the watermarked image) stably triggers the shallow decoder to output the watermark message. During the watermark extraction, it accurately recovers the message from the watermarked image by leveraging the insensitive nature of the shallow decoder against arbitrary distortions. Our ASW is training-free, encoder-free, and noise layer-free. Experiments indicate that the watermarked images created by ASW have strong robustness against various unknown distortions. Compared to the existing ``encoder-noise layer-decoder'' approaches, ASW achieves comparable results on known distortions and better robustness on unknown distortions.
title Adversarial Shallow Watermarking
topic Computer Vision and Pattern Recognition
Multimedia
url https://arxiv.org/abs/2504.19529