Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
194 tokens/sec
GPT-4o
7 tokens/sec
Gemini 2.5 Pro Pro
45 tokens/sec
o3 Pro
4 tokens/sec
GPT-4.1 Pro
38 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

DiffWA: Diffusion Models for Watermark Attack (2306.12790v1)

Published 22 Jun 2023 in cs.MM, cs.CV, and eess.IV

Abstract: With the rapid development of deep neural networks(DNNs), many robust blind watermarking algorithms and frameworks have been proposed and achieved good results. At present, the watermark attack algorithm can not compete with the watermark addition algorithm. And many watermark attack algorithms only care about interfering with the normal extraction of the watermark, and the watermark attack will cause great visual loss to the image. To this end, we propose DiffWA, a conditional diffusion model with distance guidance for watermark attack, which can restore the image while removing the embedded watermark. The core of our method is training an image-to-image conditional diffusion model on unwatermarked images and guiding the conditional model using a distance guidance when sampling so that the model will generate unwatermarked images which is similar to original images. We conducted experiments on CIFAR-10 using our proposed models. The results shows that the model can remove the watermark with good effect and make the bit error rate of watermark extraction higher than 0.4. At the same time, the attacked image will maintain good visual effect with PSNR more than 31 and SSIM more than 0.97 compared with the original image.

Definition Search Book Streamline Icon: https://streamlinehq.com
References (30)
  1. Framework for residual diffusion watermarking based on deep networks. Expert Systems with Applications 146 (2020), 113157.
  2. Diffedit diffusion-based semantic image editing with mask guidance [preprint]. arxiv. preprint, 2022.
  3. Diffusion models beat gans on image synthesis. Advances in Neural Information Processing Systems 34 (2021), 8780–8794.
  4. Real-time attacks on robust watermarking tools in the wild by cnn. Journal of Realtime Image Processing 17, 3 (2020), 631–641.
  5. Generative adversarial nets. In Advances in neural information processing systems (2014), 2672–2680.
  6. Robust image watermarking based on generative adversarial network. China Communications 17, 11 (2020), 131–140.
  7. Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition (2016), pp. 770–778.
  8. Denoising diffusion probabilistic models. Advances in Neural Information Processing Systems 33 (2020), 6840–6851.
  9. Cifar-10 (canadian institute for advanced research).
  10. Convolutional neural network-based digital image watermarking adaptive to the resolution of image and watermark. Applied Sciences 10 (2020), 19.
  11. Repaint inpainting using denoising diffusion probabilistic models. In Proceedings of the IEEECVF Conference on Computer Vision and Pattern Recognition (2022), pp. 11461–11471.
  12. Diffusion probabilistic models for 3d point cloud generation. In Proceedings of the IEEECVF Conference on Computer Vision and Pattern Recognition (2021), pp. 2837–2845.
  13. Local geometric distortions resilient watermarking scheme based on symmetry. IEEE Trans. on Circuits and Systems for Video Technology 31, 12 (2021), 4826–4839.
  14. Wan watermarking attack network. 2020.
  15. Improved denoising diffusion probabilistic models. arxiv. preprint, 2021.
  16. Diffusion models for adversarial purification. arxiv. preprint, 2022.
  17. Adversarial machine learning against digital watermarking. In Proc. of the 26th European Signal Processing Conf. (EUSIPCO) (Rome, 2018), IEEE, pp. 519–523.
  18. Ntire 2022 image inpainting challenge report. In Proceedings of the IEEECVF Conference on Computer Vision and Pattern Recognition (2022), pp. 1150–1182.
  19. Palette Image-to-image diffusion models. In NeurIPS 2021 Workshop on Deep Generative Models and Downstream Applications, 2021.
  20. Image super-resolution via iterative refinement. preprint, 2021.
  21. Deep unsupervised learning using nonequilibrium thermodynamics. In International Conference on Machine Learning (2015), pp. 2256–2265.
  22. Denoising diffusion implicit models. In International Conference on Learning Representations (2021).
  23. Generative modeling by estimating gradients of the data distribution, 2020.
  24. Score-based generative modeling through stochastic differential equations. 2020.
  25. S3rp self-supervised super-resolution and prediction for advection-diffusion process. arxiv. preprint, 2021.
  26. Guided diffusion model for adversarial purification. arxiv. preprint, 2022.
  27. Image quality assessment from error visibility to structural similarity. ieee trans. Image Process 13, 4 (2004), 600–612.
  28. Diffusion probabilistic model made slim. arxiv. preprint, 2022.
  29. histogram-based 2bin m-ary image digital watermarking algorithm. Acta Electronica Sinica 48, 3 (2020), 531–537.
  30. Hiding data with deep networks. In Proc. of the 15th European Conf. on Computer Vision (ECCV) (Munich, 2018), Springer, pp. 682–697.
Citations (4)

Summary

We haven't generated a summary for this paper yet.