Please use this identifier to cite or link to this item:
https://hdl.handle.net/10356/184414
Title: | Adversarial attack for robust watermark protection against inpainting-based and blind watermark removers | Authors: | Lyu, Mingzhi Huang, Yi Kong, Adams Wai Kin |
Keywords: | Computer and Information Science | Issue Date: | 2023 | Source: | Lyu, M., Huang, Y. & Kong, A. W. K. (2023). Adversarial attack for robust watermark protection against inpainting-based and blind watermark removers. 31st ACM International Conference on Multimedia (MM 2023), 8396-8405. https://dx.doi.org/10.1145/3581783.3612034 | Project: | NTU-ACE2020-03 | Conference: | 31st ACM International Conference on Multimedia (MM 2023) | Abstract: | The rise of social media platforms, especially those focusing on image sharing, has made visible watermarks increasingly important in protecting image copyrights. However, multiple studies have revealed that watermarks are vulnerable to both inpainting-based removers and blind watermark removers. Though two adversarial attack methods have been proposed to defend against watermark removers, they are tailored to a particular type of removers in a white-box setting, which significantly limits their practicality and applicability. To date, there is no adversarial attack method that can protect watermarks against the two types of watermark removers simultaneously. In this paper, we propose a novel method, named Adversarial Watermark Defender with Attribution-Guided Perturbation (AWD-AGP), that defends against both inpainting-based and blind watermark removers under a black-box setting. AWD-AGP is the first watermark protection method employing adversarial location. The adversarial location is generated by a Watermark Positioning Network, which predicts an optimal location for watermark placement, making watermark removal challenging for inpainting-based removers. Since inpainting-based removers and blind watermark removers exploit information in different regions of an image to perform removal, we propose an attribution-guided scheme, which automatically assigns attack strengths to different pixels against different removers. With this design, the generated perturbation can attack the two types of watermark removers concurrently. Experiments on seven models, including four inpainting-based removers and three blind watermark removers demonstrate the effectiveness of AWD-AGP. | URI: | https://hdl.handle.net/10356/184414 | ISBN: | 9798400701085 | DOI: | 10.1145/3581783.3612034 | DOI (Related Dataset): | 10.21979/N9/JNH3P4 | Schools: | College of Computing and Data Science | Research Centres: | Rapid-Rich Object Search (ROSE) Lab | Rights: | © 2023 Copyright held by the owner/author(s). This work is licensed under a Creative Commons Attribution-NonCommercial International 4.0 License. | Fulltext Permission: | open | Fulltext Availability: | With Fulltext |
Appears in Collections: | CCDS Conference Papers |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
3581783.3612034.pdf | 6.81 MB | Adobe PDF | View/Open |
SCOPUSTM
Citations
50
2
Updated on May 1, 2025
Page view(s)
28
Updated on May 6, 2025
Google ScholarTM
Check
Altmetric
Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.