FDDWAN: A Frequency-Decoupled Diffusion Network for Watermarking Attack

📅 2026-07-30
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Existing methods for invisible watermark removal struggle to effectively suppress watermarks while preserving visual image quality. This work proposes a coarse-to-fine frequency-decoupled diffusion network that innovatively integrates wavelet-based frequency decomposition with diffusion modeling. Specifically, it first applies targeted attack strategies to high- and low-frequency subbands in the wavelet domain, then employs a frequency-aware residual diffusion module to selectively refine only the watermark-related residuals. Evaluated on CelebA and ImageNet, the proposed method consistently outperforms both conventional and learning-based attack approaches across four mainstream watermarking schemes, achieving a superior trade-off between watermark removal efficacy and content fidelity.
📝 Abstract
Existing invisible watermark removal methods often struggle to accurately capture the watermark-bearing features, leading to an unfavorable trade-off between watermark suppression and perceptual fidelity. In this paper, we propose the Frequency-Decoupled Diffusion Watermark Attack Network (FDDWAN), a coarse-to-fine framework that performs watermark removal through wavelet-domain decomposition and residual diffusion refinement. In the initial stage, the Wavelet-based Frequency-domain Preliminary Attack Module (WFPAM) decomposes the watermarked image into low- and high-frequency subbands and applies frequency-specific attack strategies tailored to their respective contributions to watermark robustness and perceptual quality. In the next stage, the Frequency-domain Residual Diffusion Attack Module (FRDAM) separately models the residual distributions between the preliminarily attacked outputs and the corresponding watermark-free references during training. Rather than reconstructing the entire image, FRDAM selectively refines frequency-domain residuals, directing the diffusion process toward the remaining watermark related discrepancies while minimizing modifications to image content. Extensive experiments on CelebA and ImageNet across four representative watermarking schemes demonstrate that FDDWAN achieves a more favorable trade-off between watermark removal effectiveness and visual fidelity than conventional and learning-based attack methods.
Problem

Research questions and friction points this paper is trying to address.

watermark removal
perceptual fidelity
invisible watermarking
frequency-domain features
watermark suppression
Innovation

Methods, ideas, or system contributions that make the work stand out.

frequency-decoupled
diffusion model
watermark removal
wavelet decomposition
residual refinement
🔎 Similar Papers
No similar papers found.
C
Chunpeng Wang
Qilu University of Technology (Shandong Academy of Sciences), Jinan, Shandong Province, China
Y
Yuxin Li
Qilu University of Technology (Shandong Academy of Sciences), Jinan, Shandong Province, China
X
Xiaoyu Wang
Dalian Maritime University, Dalian, Liaoning Province, China
Jidong Yang
Jidong Yang
The University of Texas at Dallas; China University of Petroleum (East China)
Exploration SeismologyEarthquake SeismologyComputational Seismology
S
Suo Gao
Dalian Polytechnic University, Dalian, Liaoning Province, China
Q
Qi Li
Qilu University of Technology (Shandong Academy of Sciences), Jinan, Shandong Province, China