SSyncOA: Self-synchronizing Object-aligned Watermarking to Resist Cropping-paste Attacks

Chengxin Zhao,Hefei Ling,Sijing Xie,Han Fang,Yaokun Fang,Nan Sun
2024-05-06
Abstract:Modern image processing tools have made it easy for attackers to crop the region or object of interest in images and paste it into other images. The challenge this cropping-paste attack poses to the watermarking technology is that it breaks the synchronization of the image watermark, introducing multiple superimposed desynchronization distortions, such as rotation, scaling, and translation. However, current watermarking methods can only resist a single type of desynchronization and cannot be applied to protect the object's copyright under the cropping-paste attack. With the finding that the key to resisting the cropping-paste attack lies in robust features of the object to protect, this paper proposes a self-synchronizing object-aligned watermarking method, called SSyncOA. Specifically, we first constrain the watermarked region to be aligned with the protected object, and then synchronize the watermark's translation, rotation, and scaling distortions by normalizing the object invariant features, i.e., its centroid, principal orientation, and minimum bounding square, respectively. To make the watermark embedded in the protected object, we introduce the object-aligned watermarking model, which incorporates the real cropping-paste attack into the encoder-noise layer-decoder pipeline and is optimized end-to-end. Besides, we illustrate the effect of different desynchronization distortions on the watermark training, which confirms the necessity of the self-synchronization process. Extensive experiments demonstrate the superiority of our method over other SOTAs.
Computer Vision and Pattern Recognition
What problem does this paper attempt to address?
The problems that this paper attempts to solve are as follows: Modern image - processing tools enable attackers to easily crop and paste specific regions or objects in an image, thus destroying the synchronization of image watermarks and introducing multiple superimposed desynchronization distortions (such as rotation, scaling and translation). Existing watermarking techniques can only resist a single type of desynchronization distortion and cannot effectively protect the copyright of objects under crop - paste attacks. Specifically, the paper proposes solutions to the following problems: 1. **Crop - paste attack**: This type of attack will destroy the synchronization of image watermarks, resulting in the failure of copyright authentication. The multiple distortions introduced by the attack (such as cropping, translation, rotation and scaling) make it difficult for existing watermarking methods to deal with. 2. **Geometric synchronization challenge**: In order to resist crop - paste attacks, it is necessary to solve the geometric synchronization problem of the watermark area to ensure that the watermark remains consistent during the embedding and extraction processes. 3. **Object - level copyright protection**: Traditional watermarking methods are usually applied to the entire image, and object - level editing (such as cropping and pasting specific objects) will cause the watermark to become invalid. Therefore, a method that can provide copyright protection at the object level is required. To solve these problems, the paper proposes a self - synchronized object - aligned watermarking scheme (SSyncOA), which is implemented through the following steps: - **Self - synchronization process (SSync)**: By normalizing the invariant features of the object (such as the centroid, the principal direction and the minimum bounding box), the geometric synchronization of the watermark area is achieved, thereby resisting distortions such as cropping, translation, rotation and scaling. - **Object - aligned watermarking model (OA)**: Apply the self - synchronization process to the inputs of the encoder and decoder to ensure that watermark embedding and extraction are carried out within the synchronized object area, and optimize the model through end - to - end training. Through these methods, SSyncOA can effectively resist crop - paste attacks and provide stronger copyright protection at the object level.