Adversarial Attack for Robust Watermark Protection Against Inpainting-based and Blind Watermark Removers

被引:0
|
作者
Lyu, Mingzhi [1 ]
Huang, Yi [1 ]
Kong, Adams Wai-Kin [1 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
来源
PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023 | 2023年
关键词
Watermark; inpainting-based watermark remover; blind watermark remover; adversarial attack;
D O I
10.1145/3581783.3612034
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The rise of social media platforms, especially those focusing on image sharing, has made visible watermarks increasingly important in protecting image copyrights. However, multiple studies have revealed that watermarks are vulnerable to both inpainting-based removers and blind watermark removers. Though two adversarial attack methods have been proposed to defend against watermark removers, they are tailored to a particular type of removers in a white-box setting, which significantly limits their practicality and applicability. To date, there is no adversarial attack method that can protect watermarks against the two types of watermark removers simultaneously. In this paper, we propose a novel method, named Adversarial Watermark Defender with Attribution-Guided Perturbation (AWD-AGP), that defends against both inpainting-based and blind watermark removers under a black-box setting. AWD-AGP is the first watermark protection method employing adversarial location. The adversarial location is generated by a Watermark Positioning Network, which predicts an optimal location for watermark placement, making watermark removal challenging for inpainting-based removers. Since inpainting-based removers and blind watermark removers exploit information in different regions of an image to perform removal, we propose an attribution-guided scheme, which automatically assigns attack strengths to different pixels against different removers. With this design, the generated perturbation can attack the two types of watermark removers concurrently. Experiments on seven models, including four inpainting-based removers and three blind watermark removers demonstrate the effectiveness of AWD-AGP.
引用
收藏
页码:8396 / 8405
页数:10
相关论文
共 50 条
  • [31] BlindNet backdoor: Attack on deep neural network using blind watermark
    Kwon, Hyun
    Kim, Yongchul
    MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (05) : 6217 - 6234
  • [32] Copyright protection algorithm based on fusion watermark
    Ni, RG
    Liu, JQ
    Ruan, QQ
    PROCEEDINGS OF 2003 INTERNATIONAL CONFERENCE ON NEURAL NETWORKS & SIGNAL PROCESSING, PROCEEDINGS, VOLS 1 AND 2, 2003, : 1529 - 1532
  • [33] Robust watermark model based on subliminal channel
    Yang, Cheng
    Liu, Jianbo
    Niu, Yaqing
    CIS: 2007 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PROCEEDINGS, 2007, : 931 - 934
  • [34] Fractal transform based large digital watermark embedding and robust full blind extraction
    Dugelay, J.-L.
    Roche, S.
    International Conference on Multimedia Computing and Systems -Proceedings, 1999, 2 : 1003 - 1004
  • [35] LMS-based attack on watermark public detectors
    Mansour, MF
    Tewfik, AH
    2002 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOL III, PROCEEDINGS, 2002, : 649 - 652
  • [36] Watermark based copyright protection of outsourced database
    Zhu Qin
    Yang Ying
    Le Jia-jin
    Luo Yi-shu
    10TH INTERNATIONAL DATABASE ENGINEERING AND APPLICATIONS SYMPOSIUM, PROCEEDINGS, 2006, : 301 - 305
  • [37] Method of generating robust image zero-watermark and fragile watermark based on singular value
    Li, Shao-Hua
    Feng, Jing-Ying
    Lou, Ou-Jun
    Jing, Yu
    Metallurgical and Mining Industry, 2015, 7 (09): : 740 - 744
  • [38] Watermark Removal Attack Extended to Forgery Against Correlation-Based Watermarking Schemes
    Meenpal, Toshanlal
    Bhattacharjee, A. K.
    INFORMATION SYSTEMS SECURITY, (ICISS 2015), 2015, 9478 : 463 - 479
  • [39] Fractal transform based large digital watermark embedding and robust full blind extraction
    Dugelay, JL
    Roche, S
    IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS, PROCEEDINGS VOL 2, 1999, : 1003 - 1004
  • [40] A Robust Zero-Watermark Copyright Protection Scheme Based on DWT and Image Normalization
    Shakeri, Mahsa
    Jamzad, Mansour
    ADVANCES IN IMAGE AND VIDEO TECHNOLOGY, PT II, 2011, 7088 : 359 - 370