Journal of Applied Sciences ›› 2025, Vol. 43 ›› Issue (6): 935-947.doi: 10.3969/j.issn.0255-8297.2025.06.004

• Signal and Information Processing • Previous Articles    

Active Defense Method Based on Recoverable Adversarial Watermarks

WANG Jinwei1,2,3, HUANG Wanyun1, ZHANG Jiawei1, LUO Xiangyang3, MA Bin4   

  1. 1. School of Computer Science, Nanjing University of Information Science and Technology, Nanjing 210044, Jiangsu, China;
    2. Jiangsu Collaborative Innovation Center of Atmospheric Environment and Equipment Technology, Nanjing University of Information Science and Technology, Nanjing 210044, Jiangsu, China;
    3. State Key Laboratory of Mathematical Engineering and Advanced Computing, Information Engineering University, Zhengzhou 450001, Henan, China;
    4. Shandong Provincial Key Laboratory of Computer Networks, Qilu University of Technology, Jinan 250353, Shandong, China
  • Received:2024-01-08 Published:2025-12-19

Abstract: Visible watermarks are widely adopted as an important tool for copyright protection. However, as visible watermarks follow fixed embedding rules, they are hardly resistant to destruction by neural networks, which poses significant threats and challenges to existing copyright protection methods. To solve this problem, this paper proposed an active defense method based on recoverable adversarial watermarks, which improved the anti-removal ability of visible watermarks by introducing adversarial noise, thereby forming a new and more effective copyright protection method. In addition, to address the problem that watermarks may cover important areas of the host image after embedding, a recoverable adversarial visible watermark scheme was proposed. This scheme assisted authorized users in recovering the host image by embedding the important regions of the host image as secret information into non-watermark regions, thereby improving the recoverability of adversarial visible watermarks. Experimental results demonstrate that this method can effectively attack watermark removal networks while maintaining favorable recoverability.

Key words: adversarial sample, visible watermark, watermark removal network, antiremoval

CLC Number: