Enhanced Blind Watermarking Against Black-Box Noise: Leveraging CIN Framework

Rui Ma,Mengxi Guo,Peidong Jia,Chenxuan Li,Yi Hou,Yuan Li,Xiaodong Xie,Shanghang Zhang
DOI: https://doi.org/10.1109/icme57554.2024.10687737
2024-01-01
Abstract:Blind watermarking is a technology for image copyright protection and digital fingerprinting. However, the introduction of non-differentiable noise makes it challenging to be trained end-to-end for black-box scenes. The phased training technique is used for coping with black-box noise, but it limits the performance since the encoder and decoder cannot be end-to-end optimized. This work proposes a blind watermarking framework CIN+ based on the CIN to address black-box noise. Combining the structural characteristics of an Invertible Neural Network (INN) with the two-stage strategy allows joint updates of the encoder and decoder when encountering non-differentiable noise. We utilize Noise and Gradient Propagation Gate (NGPG) modules to perform a batch-level optimization akin to the two-stage approach, allowing encoder parameters to remain unlocked, thereby enhancing the model’s ability to resist blackbox attacks. Additionally, a Pre-Extraction Module (PEM) is introduced to simplify the complexity and usability of CIN. Our experimental results reveal that CIN+ achieves a new state-of-the-art performance.
What problem does this paper attempt to address?