MBRS: Enhancing Robustness of DNN-based Watermarking by Mini-Batch of Real and Simulated JPEG Compression
Zhaoyang Jia, Han Fang, Weiming Zhang
Abstract
Based on the powerful feature extraction ability of deep learning architecture, recently, deep-learning based watermarking algorithms have been widely studied. The basic framework of such algorithm is the auto-encoder like end-to-end architecture with an encoder, a noise layer and a decoder. The key to guarantee robustness is the adversarial training with the differential noise layer. However, we found that none of the existing framework can well ensure the robustness against JPEG compression, which is non-differential but is an essential and important image processing operation. To address such limitations, we proposed a novel end-to-end training architecture, which utilizes Mini-Batch of Real and Simulated JPEG compression (MBRS) to enhance the JPEG robustness. Precisely, for different mini-batches, we randomly choose one of real JPEG, simulated JPEG and noise-free layer as the noise layer. Besides, we suggest to utilize the Squeeze-and-Excitation blocks which can learn better feature in embedding and extracting stage, and propose a "message processor" to expand the message in a more appreciate way. Meanwhile, to improve the robustness against crop attack, we propose an additive diffusion block into the network. The extensive experimental results have demonstrated the superior performance of the proposed scheme compared with the state-of-the-art algorithms. Under the JPEG compression with quality factor , our models achieve a bit error rate less than 0.01% for extracted messages, with PSNR larger than 36 for the encoded images, which shows the well-enhanced robustness against JPEG attack. Besides, under many other distortions such as Gaussian filter, crop, cropout and dropout, the proposed framework also obtains strong robustness. The code implemented by PyTorch is avaiable in https://github.com/jzyustc/MBRS.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c4549e3d-1204-4ad1-bcbb-ed4bfee9dd3fCited by top-tier papers54
- Towards Blind Watermarking: Combining Invertible and Non-invertible MechanismsRui Ma, Mengxi Guo, Yi Hou, Fan Yang et al.ACM MM 2022 · 100 citations
- Robustness of AI-Image Detectors: Fundamental Limits and Practical AttacksMehrdad Saberi, Vinu Sankar Sadasivan, Keivan Rezaei, Aounon Kumar et al.ICLR 2024 · 92 citations
- SepMark: Deep Separable Watermarking for Unified Source Tracing and Deepfake DetectionXiaoshuai Wu, Xin Liao, Bo OuACM MM 2023 · 74 citations
- Flow-Based Robust Watermarking with Invertible Noise Layer for Black-Box DistortionsHan Fang, Yupeng Qiu, Kejiang Chen, Jiyi Zhang et al.AAAI 2023 · 73 citations
- EditGuard: Versatile Image Watermarking for Tamper Localization and Copyright ProtectionXuanyu Zhang, Runyi Li, Jiwen Yu, Youmin Xu et al.CVPR 2024 · 58 citations
Builds on1
Related papers
- Distortion Agnostic Deep WatermarkingXiyang Luo, Ruohan Zhan, Huiwen Chang, Feng Yang et al.CVPR 2020
- Meta-FC: Meta-Learning with Feature Consistency for Robust and Generalizable WatermarkingYuheng Li, Weitong Chen, Chengcheng Zhu, Jiale Zhang et al.CVPR 2026
- A Novel Deep Video Watermarking Framework with Enhanced Robustness to H.264/AVC CompressionYulin Zhang, Jiangqun Ni, Wenkang Su, Xin LiaoACM MM 2023 · 25 citations
- END^2: Robust Dual-Decoder Watermarking Framework Against Non-Differentiable DistortionsNan Sun, Han Fang, Yuxing Lu, Chengxin Zhao et al.AAAI 2025 · 2 citations
- JPEG Inspired Deep LearningAhmed H. Salamah, Kaixiang Zheng, Yiwen Liu, En-Hui YangICLR 2025
