Flow-Based Robust Watermarking with Invertible Noise Layer for Black-Box Distortions
Han Fang, Yupeng Qiu, Kejiang Chen, Jiyi Zhang, Weiming Zhang, Ee-Chien Chang
Abstract
Deep learning-based digital watermarking frameworks have been widely studied recently. Most existing methods adopt an ``encoder-noise layer-decoder''-based architecture where the embedding and extraction processes are accomplished separately by the encoder and the decoder. However, one potential drawback of such a framework is that the encoder and the decoder may not be well coupled, resulting in the fact that the encoder may embed some redundant features into the host image thus influencing the invisibility and robustness of the whole algorithm. To address this limitation, this paper proposes a flow-based robust watermarking framework. The basic component of such framework is an invertible up-down-sampling neural block that can realize the embedding and extraction simultaneously. As a consequence, the encoded feature could keep high consistency with the feature that the decoder needed, which effectively avoids the embedding of redundant features. In addition, to ensure the robustness of black-box distortion, an invertible noise layer (INL) is designed to simulate the distortion and is served as a noise layer in the training stage. Benefiting from its reversibility, INL is also applied as a preprocessing before extraction to eliminate the distortion, which further improves the robustness of the algorithm. Extensive experiments demonstrate the superiority of the proposed framework in terms of visual quality and robustness. Compared with the state-of-the-art architecture, the visual quality (measured by PSNR) of the proposed framework improves by 2dB and the extraction accuracy after JPEG compression (QF=50) improves by more than 4%. Besides, the robustness against black-box distortions can be greatly achieved with more than 95% extraction accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers22
- SepMark: Deep Separable Watermarking for Unified Source Tracing and Deepfake DetectionXiaoshuai Wu, Xin Liao, Bo OuACM MM 2023 · 74 citations
- EditGuard: Versatile Image Watermarking for Tamper Localization and Copyright ProtectionXuanyu Zhang, Runyi Li, Jiwen Yu, Youmin Xu et al.CVPR 2024 · 58 citations
- V2A-Mark: Versatile Deep Visual-Audio Watermarking for Manipulation Localization and Copyright ProtectionXuanyu Zhang, Youmin Xu, Runyi Li, Jiwen Yu et al.ACM MM 2024 · 9 citations
- StableGuard: Towards Unified Copyright Protection and Tamper Localization in Latent Diffusion ModelsHaoxin Yang, Bangzhen Liu, Xuemiao Xu, Cheng Xu et al.NeurIPS 2025 · 5 citations
- CoSDA: Enhancing the Robustness of Inversion-based Generative Image Watermarking FrameworkHan Fang, Kejiang Chen, Zijin Yang, Bosen Cui et al.AAAI 2025 · 5 citations
Builds on4
- HiNet: Deep Image Hiding by Invertible NetworkJunpeng Jing, Xin Deng, Mai Xu, Jianyi Wang et al.ICCV 2021 · 301 citations
- MBRS: Enhancing Robustness of DNN-based Watermarking by Mini-Batch of Real and Simulated JPEG CompressionZhaoyang Jia, Han Fang, Weiming ZhangACM MM 2021 · 251 citations
- Robust Invertible Image SteganographyYoumin Xu, Chong Mou, Yujie Hu, Jingfen Xie et al.CVPR 2022 · 151 citations
- StegaStamp: Invisible Hyperlinks in Physical PhotographsMatthew Tancik, Ben Mildenhall, Ren NgCVPR 2020
Related papers
- IRWArt: Levering Watermarking Performance for Protecting High-quality Artwork ImagesYuanjing Luo, Tongqing Zhou, Fang Liu, Zhiping CaiWWW 2023 · 26 citations
- Distortion Agnostic Deep WatermarkingXiyang Luo, Ruohan Zhan, Huiwen Chang, Feng Yang et al.CVPR 2020
- A Novel Deep Video Watermarking Framework with Enhanced Robustness to H.264/AVC CompressionYulin Zhang, Jiangqun Ni, Wenkang Su, Xin LiaoACM MM 2023 · 25 citations
- ROAR: Reducing Inversion Error in Generative Image WatermarkingHanyi Wang, Han Fang, Shi-Lin Wang, Ee-Chien ChangICCV 2025 · 1 citation
- Ultra-high Resolution Watermarking Framework Resistant to Extreme Cropping and ScalingNan Sun, Luyu Yuan, Han Fang, Yuxing Lu et al.NeurIPS 2025 · 5 citations
