Compositional Adversarial Training for Robust Visual Watermarking

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Satheesh, Anirudh, Panaitescu-Liess, Michael-Andrei, Xu, Andrew, Milis, Georgios, Huang, Heng, Cai, Zikui, Huang, Furong
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916018094342144
author Satheesh, Anirudh
Panaitescu-Liess, Michael-Andrei
Xu, Andrew
Milis, Georgios
Huang, Heng
Cai, Zikui
Huang, Furong
author_facet Satheesh, Anirudh
Panaitescu-Liess, Michael-Andrei
Xu, Andrew
Milis, Georgios
Huang, Heng
Cai, Zikui
Huang, Furong
contents Robust watermarking is typically trained with random post-processing augmentation, but random sampling under-covers the combinatorial space of realistic attack pipelines and rarely encounters the rare compositions that actually break detection. This leads to unstable training and poor sample efficiency. We instead formulate watermark robustness as a min-max problem over a structured space of compositional transformations. We propose Compositional Adversarial Training (CAT), a plug-in framework that learns a sequential differentiable adversary that observes the current watermarked image and selects an attack family at each step to maximally disrupt message recovery. CAT combines a straight-through Gumbel-Softmax attack selection with entropy regularization, allowing the backward pass to be end-to-end differentiable and aggregate gradient information across attack families, yielding faster, smoother convergence without collapsing to a single attack mode. We evaluate CAT on post-generation watermarks VideoSeal 0.0, VideoSeal 1.0, and PixelSeal and in-generation WMAR under both single-step and two-step attack suites, on in-distribution and multiple out-of-distribution image and video benchmarks. CAT consistently outperforms random-augmentation baselines trained with the same augmentation budget, with the largest gains on hard composed attacks and OOD evaluations; improving overall watermark capacity by up to $63.5\%$ in the single-step attack setting and $13.0\%$ in the compositional setting. In the autoregressive setting, CAT improves the TPR@FPR$=1\%$ by $12\%$ on average on difficult geometric transformations. These results show that robust visual watermarking benefits from training against adaptive compositional adversaries rather than independent random corruptions.
format Preprint
id arxiv_https___arxiv_org_abs_2605_16720
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Compositional Adversarial Training for Robust Visual Watermarking
Satheesh, Anirudh
Panaitescu-Liess, Michael-Andrei
Xu, Andrew
Milis, Georgios
Huang, Heng
Cai, Zikui
Huang, Furong
Computer Vision and Pattern Recognition
Machine Learning
Robust watermarking is typically trained with random post-processing augmentation, but random sampling under-covers the combinatorial space of realistic attack pipelines and rarely encounters the rare compositions that actually break detection. This leads to unstable training and poor sample efficiency. We instead formulate watermark robustness as a min-max problem over a structured space of compositional transformations. We propose Compositional Adversarial Training (CAT), a plug-in framework that learns a sequential differentiable adversary that observes the current watermarked image and selects an attack family at each step to maximally disrupt message recovery. CAT combines a straight-through Gumbel-Softmax attack selection with entropy regularization, allowing the backward pass to be end-to-end differentiable and aggregate gradient information across attack families, yielding faster, smoother convergence without collapsing to a single attack mode. We evaluate CAT on post-generation watermarks VideoSeal 0.0, VideoSeal 1.0, and PixelSeal and in-generation WMAR under both single-step and two-step attack suites, on in-distribution and multiple out-of-distribution image and video benchmarks. CAT consistently outperforms random-augmentation baselines trained with the same augmentation budget, with the largest gains on hard composed attacks and OOD evaluations; improving overall watermark capacity by up to $63.5\%$ in the single-step attack setting and $13.0\%$ in the compositional setting. In the autoregressive setting, CAT improves the TPR@FPR$=1\%$ by $12\%$ on average on difficult geometric transformations. These results show that robust visual watermarking benefits from training against adaptive compositional adversaries rather than independent random corruptions.
title Compositional Adversarial Training for Robust Visual Watermarking
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2605.16720