AI水印能被“移植”到别人的图上,罪魁是架构
给图片加AI水印,本意是标记归属;但研究者发现,水印里那层“残差”可以被抠出来,贴到任何无关图片上,照样能解出原水印——等于你的签名能被搬到别人的作品上。之前大家只知道能这么干,不知道为什么。这篇用新指标量化了“残差可移植性”,对比多个系统后锁定:训练方式、数据这些常见变量都不背锅,真正决定水印是否容易被搬走的是模型架构。他们找出两个具体机制,能让水印证据更依赖原图、搬走就失效,并顺手做了个叫CoverLock的插件,不用改架构就能给现有系统加固。对普通用户,这不是明天能用的功能;但对做版权保护、内容溯源的技术团队,这是设计下一代防伪造水印的明确施工图。
📄 原文摘要(英文)
Neural image watermarks can be forged by extracting watermark-bearing residuals from released images and transferring them to unrelated content. While prior work has demonstrated this vulnerability, what makes these residuals transferable remains poorly understood. We formalize this vulnerability with residual transferability (RT), a metric that quantifies how well watermark evidence remains decodable after transfer across unrelated images. Through comparative analyses and controlled interventions, we find that common training-side variations do not account for the large RT differences across watermarking systems; instead, architectural design plays a central role. By contrasting high- and low-RT systems and validating their architectural differences through controlled interventions, we identify two mechanisms that strengthen the dependence of watermark evidence on the cover image, thereby suppressing the residual transferability. These findings provide concrete design guidance for developing more forgery-resistant watermarking architectures. Complementarily, for existing watermarking systems where architectural redesign is impractical, we introduce CoverLock, a plug-and-play strategy for existing watermarking systems that strengthens such image dependence without architectural redesign. Across representative watermarking systems exhibiting high residual transferability, CoverLock achieves a more favorable security--robustness trade-off than both traditional handcrafted defenses and learned classifier-based defenses.