END^2: Robust Dual-Decoder Watermarking Framework Against Non-Differentiable Distortions
Nan Sun, Han Fang, Yuxing Lu, Chengxin Zhao, Hefei Ling
摘要
DNN-based watermarking methods have rapidly advanced, with the ``Encoder-Noise Layer-Decoder'' (END) framework being the most widely used. To ensure end-to-end training, the noise layer in the framework must be differentiable. However, real-world distortions are often non-differentiable, leading to challenges in end-to-end training. Existing solutions only treat the distortion perturbation as additive noise, which does not fully integrate the effect of distortion in training. To better incorporate non-differentiable distortions into training, we propose a novel dual-decoder architecture (END^2). Unlike conventional END architecture, our method employs two structurally identical decoders: the Teacher Decoder, processing pure watermarked images, and the Student Decoder, handling distortion-perturbed images. The gradient is backpropagated only through the Teacher Decoder branch to optimize the encoder thus bypassing the problem of non-differentiability. To ensure resistance to arbitrary distortions, we enforce alignment of the two decoders' feature representations by maximizing the cosine similarity between their intermediate vectors on a hypersphere. Extensive experiments demonstrate that our scheme outperforms state-of-the-art algorithms under various non-differentiable distortions. Moreover, even without the differentiability constraint, our method surpasses baselines with a differentiable noise layer. Our approach is effective and easily implementable across all END architectures, enhancing practicality and generalizability.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Ultra-high Resolution Watermarking Framework Resistant to Extreme Cropping and ScalingNan Sun, Luyu Yuan, Han Fang, Yuxing Lu 等NeurIPS 2025 · 被引用 5 次
- Meta-FC: Meta-Learning with Feature Consistency for Robust and Generalizable WatermarkingYuheng Li, Weitong Chen, Chengcheng Zhu, Jiale Zhang 等CVPR 2026
它引用的顶会 Paper6
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec 等NeurIPS 2020 · 被引用 9,171 次
- Emerging Properties in Self-Supervised Vision TransformersMathilde Caron, Hugo Touvron, Ishan Misra, Hervé Jégou 等ICCV 2021 · 被引用 8,921 次
- Barlow Twins: Self-Supervised Learning via Redundancy ReductionJure Zbontar, Li Jing, Ishan Misra, Yann LeCun 等ICML 2021 · 被引用 2,942 次
- MBRS: Enhancing Robustness of DNN-based Watermarking by Mini-Batch of Real and Simulated JPEG CompressionZhaoyang Jia, Han Fang, Weiming ZhangACM MM 2021 · 被引用 251 次
- Towards Robust Deep Hiding Under Non-Differentiable Distortions for Practical Blind WatermarkingChaoning Zhang, Adil Karjauv, Philipp Benz, In So KweonACM MM 2021 · 被引用 54 次
相关 Paper
- Distortion Agnostic Deep WatermarkingXiyang Luo, Ruohan Zhan, Huiwen Chang, Feng Yang 等CVPR 2020
- Flow-Based Robust Watermarking with Invertible Noise Layer for Black-Box DistortionsHan Fang, Yupeng Qiu, Kejiang Chen, Jiyi Zhang 等AAAI 2023 · 被引用 73 次
- DERO: Diffusion-Model-Erasure Robust WatermarkingHan Fang, Kejiang Chen, Yupeng Qiu, Zehua Ma 等ACM MM 2024 · 被引用 6 次
- Decoupling Defense Strategies for Robust Image WatermarkingJiahui Chen, Zehang Deng, Zeyu Zhang, Chaoyang Li 等CVPR 2026 · 被引用 1 次
- Guidance Watermarking for Diffusion ModelsEnoal Gesny, Eva Giboulot, Teddy Furon, Vivien ChappelierICLR 2026 · 被引用 5 次
