Towards Robust Deep Hiding Under Non-Differentiable Distortions for Practical Blind Watermarking
Chaoning Zhang, Adil Karjauv, Philipp Benz, In So Kweon
Abstract
Data hiding is one widely used approach for proving ownership through blind watermarking. Deep learning has been widely used in data hiding, for which inserting an attack simulation layer (ASL) after the watermarked image has been widely recognized as the most effective approach for improving the pipeline robustness against distortions. Despite its wide usage, the gain of enhanced robustness from ASL is usually interpreted through the lens of augmentation, while our work explores this gain from a new perspective by disentangling the forward and backward propagation of such ASL. We find that the main influential component is forward propagation instead of backward propagation. This observation motivates us to use forward ASL to make the pipeline compatible with non-differentiable and/or black-box distortion, such as lossy (JPEG) compression and photoshop effects. Extensive experiments demonstrate the efficacy of our simple approach.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2955d11e-70a2-40ba-95b5-4eb3e49f0f0fCited by top-tier papers9
- The Stable Signature: Rooting Watermarks in Latent Diffusion ModelsPierre Fernandez, Guillaume Couairon, Hervé Jégou, Matthijs Douze et al.ICCV 2023 · 370 citations
- Watermarking Autoregressive Image GenerationNikola Jovanovic, Ismail Labiad, Tomás Soucek, Martin T. Vechev et al.NeurIPS 2025 · 21 citations
- All in One: Unifying Deepfake Detection, Tampering Localization, and Source Tracing with a Robust Landmark-Identity WatermarkJunjiang Wu, Liejun Wang, Zhiqing GuoCVPR 2026 · 4 citations
- END^2: Robust Dual-Decoder Watermarking Framework Against Non-Differentiable DistortionsNan Sun, Han Fang, Yuxing Lu, Chengxin Zhao et al.AAAI 2025 · 2 citations
- Lightweight-Mark: Rethinking Deep Learning-Based WatermarkingYupeng Qiu, Han Fang, Ee-Chien ChangICML 2025
Related papers
- Distortion Agnostic Deep WatermarkingXiyang Luo, Ruohan Zhan, Huiwen Chang, Feng Yang et al.CVPR 2020
- Flow-Based Robust Watermarking with Invertible Noise Layer for Black-Box DistortionsHan Fang, Yupeng Qiu, Kejiang Chen, Jiyi Zhang et al.AAAI 2023 · 73 citations
- Margin-based Neural Network WatermarkingByungjoo Kim, Suyoung Lee, Seanie Lee, Sooel Son et al.ICML 2023 · 21 citations
- WRATH: Turning Watermark Robustness Against Itself via a Watermark-Agnostic Black-Box Invalidation AttackNan Jiang, Juan Hu, Bangjie Sun, Terence Sim et al.S&P 2026
- THE SELF-RE-WATERMARKING TRAP: FROM EXPLOIT TO RESILIENCEVithurabiman Senthuran, Yong Xiang, Iynkaran Natgunanathan, Uthayasanker ThayasivamICLR 2026
