Where Does the Watermark Hide? Push-Pull Disentanglement for Invisible Watermark Removal

📅 2026-09-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the threat of invisible watermark removal using models trained on paired data by proposing a single-image blind watermark removal method that requires neither reference images nor secret keys. The core innovation lies in a push-pull decoupling architecture, which decomposes an image via a deep encoder into structural and auxiliary residual latent variables. An adversarial push-pull supervision strategy is employed to guide watermark separation and image reconstruction, revealing the decoder's critical dependence on the auxiliary input. Experimental results demonstrate that the proposed method reduces the average bit error rate to 0.3958 while achieving a PSNR of 31.07 dB and an SSIM of 0.9554. These findings validate the effectiveness of latent space decoupling for robust watermark removal in unknown-key scenarios.
📝 Abstract
Fixed image distortions do not cover an attacker that learns from paired clean and watermarked images. We study this paired-training threat with single-image inference: deployment uses neither the clean reference nor the watermark key, payload, or decoder. An encoder maps each image to a structural latent $g$ and an auxiliary residual latent $u$. Push supervision reconstructs the watermarked image from $D(g_w,u_w)$. Pull supervision trains the zero-auxiliary output $D(A_g(g_w;k),0)$ toward the paired clean image. At $k=1.10,u=0$, the four-method sweep gives an average BER of $0.3958$, PSNR of $31.07$ dB, and SSIM of $0.9554$. Restoring $u$ from $0$ to $0.15$ moves average BER from $0.3893$ to $0.3357$, while PSNR falls from $30.99$ to $28.23$ dB. The intervention supports decoder dependence on the auxiliary input in the evaluated setting. The accompanying theory is a conditional, post-hoc account of this behavior rather than an experimentally verified information-relocation result.
Problem

Research questions and friction points this paper is trying to address.

invisible watermark removal
paired-training threat
single-image inference
watermark disentanglement
Innovation

Methods, ideas, or system contributions that make the work stand out.

Push-Pull Disentanglement
Invisible Watermark Removal
Latent Space Decomposition
Single-Image Inference
Paired-Training Threat
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
Jidong Yang
Jidong Yang
The University of Texas at Dallas; China University of Petroleum (East China)
Exploration SeismologyEarthquake SeismologyComputational Seismology
H
Huaike Yu
Key Laboratory of Computing Power Network and Information Security, Ministry of Education, Shandong Computer Science Center, and Shandong Provincial Key Laboratory of Industrial Network and Information System Security, Shandong Fundamental Research Center for Computer Science, Qilu University of Technology (Shandong Academy of Sciences), Jinan 250353, China
Qi Li
Qi Li
Institute of Automation, Chinese Academy of Sciences
pattern recognitioncomputer vision
C
Chunpeng Wang
Key Laboratory of Computing Power Network and Information Security, Ministry of Education, Shandong Computer Science Center, and Shandong Provincial Key Laboratory of Industrial Network and Information System Security, Shandong Fundamental Research Center for Computer Science, Qilu University of Technology (Shandong Academy of Sciences), Jinan 250353, China
Yuantian Miao
Yuantian Miao
University of Newcastle, NSW Australia
ML Security & PrivacyNetwork Traffic ClassificationNetwork Security
S
Suo Gao
School of Information Science and Engineering, Dalian Polytechnic University, Dalian 116034, China
Xiao Chen
Xiao Chen
The University of Newcastle
Software SecurityMobile SecurityAI for Security