Adversarial Attack for Robust Watermark Protection Against Inpainting-based and Blind Watermark Removers

被引:0
|
作者
Lyu, Mingzhi [1 ]
Huang, Yi [1 ]
Kong, Adams Wai-Kin [1 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
关键词
Watermark; inpainting-based watermark remover; blind watermark remover; adversarial attack;
D O I
10.1145/3581783.3612034
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The rise of social media platforms, especially those focusing on image sharing, has made visible watermarks increasingly important in protecting image copyrights. However, multiple studies have revealed that watermarks are vulnerable to both inpainting-based removers and blind watermark removers. Though two adversarial attack methods have been proposed to defend against watermark removers, they are tailored to a particular type of removers in a white-box setting, which significantly limits their practicality and applicability. To date, there is no adversarial attack method that can protect watermarks against the two types of watermark removers simultaneously. In this paper, we propose a novel method, named Adversarial Watermark Defender with Attribution-Guided Perturbation (AWD-AGP), that defends against both inpainting-based and blind watermark removers under a black-box setting. AWD-AGP is the first watermark protection method employing adversarial location. The adversarial location is generated by a Watermark Positioning Network, which predicts an optimal location for watermark placement, making watermark removal challenging for inpainting-based removers. Since inpainting-based removers and blind watermark removers exploit information in different regions of an image to perform removal, we propose an attribution-guided scheme, which automatically assigns attack strengths to different pixels against different removers. With this design, the generated perturbation can attack the two types of watermark removers concurrently. Experiments on seven models, including four inpainting-based removers and three blind watermark removers demonstrate the effectiveness of AWD-AGP.
引用
收藏
页码:8396 / 8405
页数:10
相关论文
共 50 条
  • [1] Adversarial watermark: A robust and reliable watermark against removal
    Wang, Jinwei
    Huang, Wanyun
    Zhang, Jiawei
    Luo, Xiangyang
    Ma, Bin
    Journal of Information Security and Applications, 2024, 82
  • [2] Adversarial watermark: A robust and reliable watermark against removal
    Wang, Jinwei
    Huang, Wanyun
    Zhang, Jiawei
    Luo, Xiangyang
    Ma, Bin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 82
  • [3] Robust Adversarial Watermark Defending Against GAN Synthesization Attack
    Xu, Shengwang
    Qiao, Tong
    Xu, Ming
    Wang, Wei
    Zheng, Ning
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 351 - 355
  • [4] FAWA: Fast Adversarial Watermark Attack
    Jiang, Hao
    Yang, Jintao
    Hua, Guang
    Li, Lixia
    Wang, Ying
    Tu, Shenghui
    Xia, Song
    IEEE TRANSACTIONS ON COMPUTERS, 2024, 73 (02) : 301 - 313
  • [5] ModelShield: Adaptive and Robust Watermark Against Model Extraction Attack
    Pang, Kaiyi
    Qi, Tao
    Wu, Chuhan
    Bai, Minhao
    Jiang, Minghu
    Huang, Yongfeng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 1767 - 1782
  • [6] Algorithm for robust blind image watermark
    Cai, S. (caisu@vrlab.buaa.edu.cn), 1600, Beijing University of Aeronautics and Astronautics (BUAA) (29):
  • [7] MEA-Defender: A Robust Watermark against Model Extraction Attack
    Lv, Peizhuo
    Ma, Hualong
    Chen, Kai
    Zhou, Jiachen
    Zhang, Shengzhi
    Liang, Ruigang
    Zhu, Shenchen
    Li, Pan
    Zhang, Yingjun
    45TH IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP 2024, 2024, : 2515 - 2533
  • [8] A robust watermark scheme for copyright protection
    Lin, Chu-Hsing
    Liu, Jung-Chun
    Shih, Chih-Hsiong
    Lee, Yan-Wei
    MUE: 2008 INTERNATIONAL CONFERENCE ON MULTIMEDIA AND UBIQUITOUS ENGINEERING, PROCEEDINGS, 2008, : 132 - 137
  • [9] The blind pattern matching attack on watermark systems
    Petitcolas, FAP
    Kirovski, D
    2002 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, VOLS I-IV, PROCEEDINGS, 2002, : 3740 - 3743
  • [10] Making Adversarial Attack Imperceptible in Frequency Domain: A Watermark-based Framework
    Zhang, Hanxiu
    Cao, Guitao
    Zhang, Xinyue
    Xiang, Jing
    Wu, Chunwei
    2023 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, ICME, 2023, : 43 - 48