跳到正文
原文
HuggingFace Daily Papers(社区热门论文)· HuggingFace Daily Papers(社区热门论文)·· 10 天前AI 评分38

神经图像水印中的残差可迁移性研究:CoverLock 防御策略

AI 导读

研究提出残差可迁移性(RT)指标,量化神经图像水印证据在跨图像迁移后的可解码程度,发现架构设计而非训练侧变化是 RT 差异的主因,并识别出两种强化水印证据对载体图像依赖的机制。针对难以重新设计架构的现有水印系统,作者提出即插即用策略 CoverLock,在高 RT 水印系统上实现了优于传统手工防御和基于学习分类器防御的安全—鲁棒性权衡。

正文

View PDF HTML (experimental)

Abstract:Neural image watermarks can be forged by extracting watermark-bearing residuals from released images and transferring them to unrelated content. While prior work has demonstrated this vulnerability, what makes these residuals transferable remains poorly understood. We formalize this vulnerability with \textbf{residual transferability (RT)}, a metric that quantifies how well watermark evidence remains decodable after transfer across unrelated images. Through comparative analyses and controlled interventions, we find that common training-side variations do not account for the large RT differences across watermarking systems; instead, architectural design plays a central role. By contrasting high- and low-RT systems and validating their architectural differences through controlled interventions, we identify two mechanisms that strengthen the dependence of watermark evidence on the cover image, thereby suppressing the residual transferability. These findings provide concrete design guidance for developing more forgery-resistant watermarking architectures. Complementarily, for existing watermarking systems where architectural redesign is impractical, we introduce \textbf{CoverLock}, a plug-and-play strategy for existing watermarking systems that strengthens such image dependence without architectural redesign. Across representative watermarking systems exhibiting high residual transferability, CoverLock achieves a more favorable security--robustness trade-off than both traditional handcrafted defenses and learned classifier-based defenses.
Comments: Preprint
Subjects: Cryptography and Security (cs.CR); Computer Vision and Pattern Recognition (cs.CV)
Cite as: arXiv:2609.32241 [cs.CR]
  (or arXiv:2609.32241v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2609.32241

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Ziping Dong [view email]
[v1] Sat, 26 Sep 2026 04:59:33 UTC (1,630 KB)

来源:HuggingFace Daily Papers(社区热门论文) · arxiv.org