Please use this identifier to cite or link to this item: https://hdl.handle.net/10356/184414
Title: Adversarial attack for robust watermark protection against inpainting-based and blind watermark removers
Authors: Lyu, Mingzhi
Huang, Yi
Kong, Adams Wai Kin
Keywords: Computer and Information Science
Issue Date: 2023
Source: Lyu, M., Huang, Y. & Kong, A. W. K. (2023). Adversarial attack for robust watermark protection against inpainting-based and blind watermark removers. 31st ACM International Conference on Multimedia (MM 2023), 8396-8405. https://dx.doi.org/10.1145/3581783.3612034
Project: NTU-ACE2020-03
Conference: 31st ACM International Conference on Multimedia (MM 2023)
Abstract: The rise of social media platforms, especially those focusing on image sharing, has made visible watermarks increasingly important in protecting image copyrights. However, multiple studies have revealed that watermarks are vulnerable to both inpainting-based removers and blind watermark removers. Though two adversarial attack methods have been proposed to defend against watermark removers, they are tailored to a particular type of removers in a white-box setting, which significantly limits their practicality and applicability. To date, there is no adversarial attack method that can protect watermarks against the two types of watermark removers simultaneously. In this paper, we propose a novel method, named Adversarial Watermark Defender with Attribution-Guided Perturbation (AWD-AGP), that defends against both inpainting-based and blind watermark removers under a black-box setting. AWD-AGP is the first watermark protection method employing adversarial location. The adversarial location is generated by a Watermark Positioning Network, which predicts an optimal location for watermark placement, making watermark removal challenging for inpainting-based removers. Since inpainting-based removers and blind watermark removers exploit information in different regions of an image to perform removal, we propose an attribution-guided scheme, which automatically assigns attack strengths to different pixels against different removers. With this design, the generated perturbation can attack the two types of watermark removers concurrently. Experiments on seven models, including four inpainting-based removers and three blind watermark removers demonstrate the effectiveness of AWD-AGP.
URI: https://hdl.handle.net/10356/184414
ISBN: 9798400701085
DOI: 10.1145/3581783.3612034
DOI (Related Dataset): 10.21979/N9/JNH3P4
Schools: College of Computing and Data Science 
Research Centres: Rapid-Rich Object Search (ROSE) Lab 
Rights: © 2023 Copyright held by the owner/author(s). This work is licensed under a Creative Commons Attribution-NonCommercial International 4.0 License.
Fulltext Permission: open
Fulltext Availability: With Fulltext
Appears in Collections:CCDS Conference Papers

Files in This Item:
File Description SizeFormat 
3581783.3612034.pdf6.81 MBAdobe PDFView/Open

SCOPUSTM   
Citations 50

2
Updated on May 1, 2025

Page view(s)

28
Updated on May 6, 2025

Google ScholarTM

Check

Altmetric


Plumx

Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.