应用科学学报 ›› 2025, Vol. 43 ›› Issue (6): 935-947.doi: 10.3969/j.issn.0255-8297.2025.06.004

• 信号与信息处理 • 上一篇    

基于可恢复对抗水印的主动防御方法

王金伟1,2,3, 黄琬云1, 张家伟1, 罗向阳3, 马宾4   

  1. 1. 南京信息工程大学 计算机学院, 江苏 南京 210044;
    2. 南京信息工程大学 江苏省大气环境与装备技术协同创新中心, 江苏 南京 210044;
    3. 信息工程大学 数学工程与高级计算国家重点实验室, 河南 郑州 450001;
    4. 齐鲁工业大学 山东省计算机网络重点实验室, 山东 济南 250353
  • 收稿日期:2024-01-08 发布日期:2025-12-19
  • 通信作者: 王金伟,教授,研究方向为信息安全。E-mail:wjwei_2004@163.com E-mail:wjwei_2004@163.com
  • 基金资助:
    国家自然科学基金(No. 62072250, No. 61772281, No. 61702235, No. U163617, No. U1804263, No. 62172435, No. 61872203, No. 61802212);中国中原科技创新领军人才项目(No. 214200510019);河南省科技人才计划(No. 2018JR0018);广东省信息安全技术重点实验室开放项目(No. 2020B1212060078)以及江苏省高等教育机构(PAPD)优先学术项目发展基金。

Active Defense Method Based on Recoverable Adversarial Watermarks

WANG Jinwei1,2,3, HUANG Wanyun1, ZHANG Jiawei1, LUO Xiangyang3, MA Bin4   

  1. 1. School of Computer Science, Nanjing University of Information Science and Technology, Nanjing 210044, Jiangsu, China;
    2. Jiangsu Collaborative Innovation Center of Atmospheric Environment and Equipment Technology, Nanjing University of Information Science and Technology, Nanjing 210044, Jiangsu, China;
    3. State Key Laboratory of Mathematical Engineering and Advanced Computing, Information Engineering University, Zhengzhou 450001, Henan, China;
    4. Shandong Provincial Key Laboratory of Computer Networks, Qilu University of Technology, Jinan 250353, Shandong, China
  • Received:2024-01-08 Published:2025-12-19

摘要: 可见水印作为版权保护的重要工具被广泛应用。然而,由于可见水印服从既定的嵌入规则,很难抵抗神经网络的破坏,这给现有版权保护方法带来了巨大的威胁和挑战。为解决这一问题,本文提出了一种基于可恢复对抗水印的主动防御方法,通过引入对抗噪声提高可见水印的抗去除能力,从而形成一种新的更有效的版权保护手段。此外,为解决水印嵌入后可能会遮盖宿主图像重要区域的问题,本文提出了一种可恢复的对抗性可见水印方案。该方案通过将宿主图像重要区域作为秘密信息嵌入到非水印区域,来帮助授权用户恢复宿主图像,从而提升对抗性可见水印的可恢复性。实验证明,该方法可以在攻击水印去除网络的同时保证良好的可恢复性。

关键词: 对抗样本, 可见水印, 水印去除网络, 抗去除

Abstract: Visible watermarks are widely adopted as an important tool for copyright protection. However, as visible watermarks follow fixed embedding rules, they are hardly resistant to destruction by neural networks, which poses significant threats and challenges to existing copyright protection methods. To solve this problem, this paper proposed an active defense method based on recoverable adversarial watermarks, which improved the anti-removal ability of visible watermarks by introducing adversarial noise, thereby forming a new and more effective copyright protection method. In addition, to address the problem that watermarks may cover important areas of the host image after embedding, a recoverable adversarial visible watermark scheme was proposed. This scheme assisted authorized users in recovering the host image by embedding the important regions of the host image as secret information into non-watermark regions, thereby improving the recoverability of adversarial visible watermarks. Experimental results demonstrate that this method can effectively attack watermark removal networks while maintaining favorable recoverability.

Key words: adversarial sample, visible watermark, watermark removal network, antiremoval

中图分类号: