Adversarial Attack for Robust Watermark Protection Against Inpainting-based and Blind Watermark Removers

被引:0
|
作者
Lyu, Mingzhi [1 ]
Huang, Yi [1 ]
Kong, Adams Wai-Kin [1 ]
机构
[1] Nanyang Technol Univ, Singapore, Singapore
来源
PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023 | 2023年
关键词
Watermark; inpainting-based watermark remover; blind watermark remover; adversarial attack;
D O I
10.1145/3581783.3612034
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The rise of social media platforms, especially those focusing on image sharing, has made visible watermarks increasingly important in protecting image copyrights. However, multiple studies have revealed that watermarks are vulnerable to both inpainting-based removers and blind watermark removers. Though two adversarial attack methods have been proposed to defend against watermark removers, they are tailored to a particular type of removers in a white-box setting, which significantly limits their practicality and applicability. To date, there is no adversarial attack method that can protect watermarks against the two types of watermark removers simultaneously. In this paper, we propose a novel method, named Adversarial Watermark Defender with Attribution-Guided Perturbation (AWD-AGP), that defends against both inpainting-based and blind watermark removers under a black-box setting. AWD-AGP is the first watermark protection method employing adversarial location. The adversarial location is generated by a Watermark Positioning Network, which predicts an optimal location for watermark placement, making watermark removal challenging for inpainting-based removers. Since inpainting-based removers and blind watermark removers exploit information in different regions of an image to perform removal, we propose an attribution-guided scheme, which automatically assigns attack strengths to different pixels against different removers. With this design, the generated perturbation can attack the two types of watermark removers concurrently. Experiments on seven models, including four inpainting-based removers and three blind watermark removers demonstrate the effectiveness of AWD-AGP.
引用
收藏
页码:8396 / 8405
页数:10
相关论文
共 50 条
  • [41] A digital watermark based on blind signal separation algorithm
    Yang Su-min
    Wang Jia-zhen
    Zhang Zheng-bao
    Ding Guo-liang
    2006 8TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, VOLS 1-4, 2006, : 2542 - +
  • [42] Wavelet-based blind watermark retrieval technique
    Wang, HJM
    Su, PC
    Kuo, CCJ
    MULTIMEDIA SYSTEMS AND APPLICATIONS-BOOK, 1999, 3528 : 440 - 451
  • [43] A Novel Blind Watermark Algorithm Based On SVD And DCT
    Liu, Feng
    Han, Ke
    Wang, Chang Zheng
    2009 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND INTELLIGENT SYSTEMS, PROCEEDINGS, VOL 4, 2009, : 283 - +
  • [44] Robust blind watermark detection algorithm of 3D motion
    Shi, Lie
    Ye, Lu
    Huang, Xiang-Jun
    Pan, Zhi-Geng
    Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science), 2005, 39 (03): : 317 - 321
  • [45] A novel blind grayscale watermark algorithm based on SVD
    Ma, Xiaohu
    Shen, Xiaofeng
    2008 INTERNATIONAL CONFERENCE ON AUDIO, LANGUAGE AND IMAGE PROCESSING, VOLS 1 AND 2, PROCEEDINGS, 2008, : 1063 - 1068
  • [46] A Blind Digital Watermark Method Based on SVD and Chaos
    Song, Jianhua
    Song, Jianwei
    Bao, Yuhua
    2012 INTERNATIONAL WORKSHOP ON INFORMATION AND ELECTRONICS ENGINEERING, 2012, 29 : 285 - 289
  • [47] An adaptive blind scheme for readable watermark based on ALE
    Tang, Shifu
    Ma, Hong
    Song, Enbin
    Su, Liyun
    2006 8TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, VOLS 1-4, 2006, : 2982 - +
  • [48] A Provable Watermark-based Copyright Protection Scheme
    Ting, Pei-Yih
    Huang, Shao-Da
    Wu, Tzong-Sun
    Lin, Han-Yu
    2015 10TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS), 2015, : 124 - 129
  • [49] Adaptive Threshold Based Robust Watermark Detection Method
    Karabat, Cagatay
    DIGITAL WATERMARKING, 2009, 5450 : 139 - 151
  • [50] Watermark-based copyright protection system security
    Kwok, SH
    COMMUNICATIONS OF THE ACM, 2003, 46 (10) : 98 - 101