END^2: Robust Dual-Decoder Watermarking Framework Against Non-Differentiable Distortions
Nan Sun, Han Fang, Yuxing Lu, Chengxin Zhao, Hefei Ling
Abstract
DNN-based watermarking methods have rapidly advanced, with the ``Encoder-Noise Layer-Decoder'' (END) framework being the most widely used. To ensure end-to-end training, the noise layer in the framework must be differentiable. However, real-world distortions are often non-differentiable, leading to challenges in end-to-end training. Existing solutions only treat the distortion perturbation as additive noise, which does not fully integrate the effect of distortion in training. To better incorporate non-differentiable distortions into training, we propose a novel dual-decoder architecture (END^2). Unlike conventional END architecture, our method employs two structurally identical decoders: the Teacher Decoder, processing pure watermarked images, and the Student Decoder, handling distortion-perturbed images. The gradient is backpropagated only through the Teacher Decoder branch to optimize the encoder thus bypassing the problem of non-differentiability. To ensure resistance to arbitrary distortions, we enforce alignment of the two decoders' feature representations by maximizing the cosine similarity between their intermediate vectors on a hypersphere. Extensive experiments demonstrate that our scheme outperforms state-of-the-art algorithms under various non-differentiable distortions. Moreover, even without the differentiability constraint, our method surpasses baselines with a differentiable noise layer. Our approach is effective and easily implementable across all END architectures, enhancing practicality and generalizability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4d3fd084-7910-4362-b90f-bee86a1f7101Cited by top-tier papers2
- Ultra-high Resolution Watermarking Framework Resistant to Extreme Cropping and ScalingNan Sun, Luyu Yuan, Han Fang, Yuxing Lu et al.NeurIPS 2025 · 5 citations
- Meta-FC: Meta-Learning with Feature Consistency for Robust and Generalizable WatermarkingYuheng Li, Weitong Chen, Chengcheng Zhu, Jiale Zhang et al.CVPR 2026
Builds on6
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec et al.NeurIPS 2020 · 9,171 citations
- Emerging Properties in Self-Supervised Vision TransformersMathilde Caron, Hugo Touvron, Ishan Misra, Hervé Jégou et al.ICCV 2021 · 8,921 citations
- Barlow Twins: Self-Supervised Learning via Redundancy ReductionJure Zbontar, Li Jing, Ishan Misra, Yann LeCun et al.ICML 2021 · 2,942 citations
- MBRS: Enhancing Robustness of DNN-based Watermarking by Mini-Batch of Real and Simulated JPEG CompressionZhaoyang Jia, Han Fang, Weiming ZhangACM MM 2021 · 251 citations
- Towards Robust Deep Hiding Under Non-Differentiable Distortions for Practical Blind WatermarkingChaoning Zhang, Adil Karjauv, Philipp Benz, In So KweonACM MM 2021 · 54 citations
Related papers
- Distortion Agnostic Deep WatermarkingXiyang Luo, Ruohan Zhan, Huiwen Chang, Feng Yang et al.CVPR 2020
- Flow-Based Robust Watermarking with Invertible Noise Layer for Black-Box DistortionsHan Fang, Yupeng Qiu, Kejiang Chen, Jiyi Zhang et al.AAAI 2023 · 73 citations
- DERO: Diffusion-Model-Erasure Robust WatermarkingHan Fang, Kejiang Chen, Yupeng Qiu, Zehua Ma et al.ACM MM 2024 · 6 citations
- Decoupling Defense Strategies for Robust Image WatermarkingJiahui Chen, Zehang Deng, Zeyu Zhang, Chaoyang Li et al.CVPR 2026 · 1 citation
- Guidance Watermarking for Diffusion ModelsEnoal Gesny, Eva Giboulot, Teddy Furon, Vivien ChappelierICLR 2026 · 5 citations
