SPFM-Net: Semantic-Prior-Guided Frequency-Constrained Mamba for Invisible Watermark Attack

📅 2026-07-30
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Existing watermark removal methods struggle to effectively model the long-range dependencies of global watermark signals, often failing to balance removal efficacy with visual fidelity. This work proposes a Mamba-based architecture that integrates semantic priors and frequency-domain constraints to address this challenge. By applying high-ratio masking to disrupt the spatial coherence of watermarks and leveraging a partially fine-tuned masked autoencoder for semantically consistent image reconstruction, the method enhances content preservation. Furthermore, it introduces multi-scale residual frequency-domain feature interaction and Mamba-driven global state-space modeling to jointly optimize spatial, spectral, and edge information. To the best of our knowledge, this is the first approach to embed semantic guidance and frequency-domain constraints within a Mamba framework, achieving state-of-the-art attack performance across multiple mainstream watermarking schemes while maintaining superior visual quality and striking an optimal balance between watermark suppression and image fidelity.
📝 Abstract
Existing watermark attacks typically rely on predefined signal-processing operations or locally constrained restoration networks, making it difficult to capture the long-range dependencies of globally distributed watermark signals and resulting in an unfavorable trade-off between removal effectiveness and visual fidelity. In this paper, we propose SPFM-Net, a semantic-prior-guided and frequency-constrained Mamba framework for invisible watermark attack. SPFM-Net first employs high-ratio masking to disrupt the spatial coherence of invisible watermark signals, and then utilizes a partially fine-tuned pretrained Masked Autoencoder to reconstruct semantically consistent image from sparse observations while suppressing watermark-related information. A Multi-scale Residual Frequency Feature Interaction module subsequently aggregates watermark-related residual features across multiple receptive fields, while adaptively suppressing responses from watermark-irrelevant regions. To further capture the long-range dependencies of globally distributed watermark signals, a lightweight Mamba-based Global State-space Feature Modeling (GSFM) unit is introduced to separate watermark-related features from natural image content and suppress the remaining watermark traces. In addition, SPFM-Net is optimized using a multi-level objective that jointly imposes spatial-, frequency-, and edge-domain constraints, enabling effective watermark suppression while preserving perceptual quality. Extensive experiments on representative spatial-domain, transform-domain, orthogonal moment-based, and deep learning-based watermarking schemes demonstrate that SPFM-Net achieves a favorable trade-off between watermark attack effectiveness and perceptual fidelity.
Problem

Research questions and friction points this paper is trying to address.

invisible watermark attack
long-range dependencies
visual fidelity
watermark removal
global watermark signals
Innovation

Methods, ideas, or system contributions that make the work stand out.

Mamba
frequency-constrained
semantic prior
invisible watermark attack
global state-space modeling
🔎 Similar Papers
No similar papers found.