Pith. sign in

REVIEW 2 cited by

Robust-Wide: Robust Watermarking against Instruction-driven Image Editing

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2402.12688 v3 pith:2B27MJNC submitted 2024-02-20 cs.CR

classification cs.CR
keywords imageeditinginstruction-drivenrobust-widewatermarkingrobustimagessemantic
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Instruction-driven image editing allows users to quickly edit an image according to text instructions in a forward pass. Nevertheless, malicious users can easily exploit this technique to create fake images, which could cause a crisis of trust and harm the rights of the original image owners. Watermarking is a common solution to trace such malicious behavior. Unfortunately, instruction-driven image editing can significantly change the watermarked image at the semantic level, making current state-of-the-art watermarking methods ineffective. To remedy it, we propose Robust-Wide, the first robust watermarking methodology against instruction-driven image editing. Specifically, we follow the classic structure of deep robust watermarking, consisting of the encoder, noise layer, and decoder. To achieve robustness against semantic distortions, we introduce a novel Partial Instruction-driven Denoising Sampling Guidance (PIDSG) module, which consists of a large variety of instruction injections and substantial modifications of images at different semantic levels. With PIDSG, the encoder tends to embed the watermark into more robust and semantic-aware areas, which remains in existence even after severe image editing. Experiments demonstrate that Robust-Wide can effectively extract the watermark from the edited image with a low bit error rate of nearly 2.6% for 64-bit watermark messages. Meanwhile, it only induces a neglectable influence on the visual quality and editability of the original images. Moreover, Robust-Wide holds general robustness against different sampling configurations and other popular image editing methods such as ControlNet-InstructPix2Pix, MagicBrush, Inpainting, and DDIM Inversion. Codes and models are available at https://github.com/hurunyi/Robust-Wide.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SuperMark: Robust and Training-free Image Watermarking via Diffusion-based Super-Resolution

    cs.CV 2024-12 conditional novelty 7.0 of 10

    A training-free watermarking framework that embeds watermarks into diffusion super-resolution noise and extracts them via DDIM inversion, reaching 99.46% bit accuracy under standard distortions and 89.29% under adapti...

  2. StyleMark: A Robust Watermarking Method for Art Style Images Against Black-Box Arbitrary Style Transfer

    cs.CV 2024-12 conditional novelty 6.0 of 10

    A watermark embedded in the style-feature statistics of an art image can be recovered from images produced by black-box arbitrary style transfer models.

Pith tools