Modern watermarking methods improved for security and capacity

Optimizing and Securing the Modern Watermarking Channel for Images

Cryptography and SecurityComputer Vision and Pattern Recognition

Summary

Watermarks hidden inside images help track where those images come from, but current systems are often limited and not very secure. The authors studied these watermarking methods and found they use a simple way to send bits, which limits how much data can be stored, and they don’t use secret keys, making them vulnerable to attacks. They developed a new system called SNW that can store more information securely without these limits by using better coding and secret keys. This could make watermarked images more reliable and harder to tamper with.

What this means in practice

  • For image hosting platforms: Embed robust, secure watermarks into images to ensure content traceability and reduce unauthorized use or distribution.
  • For digital rights management teams: Use advanced watermarking with secret keys to protect digital images from tampering or forgery with stronger theoretical guarantees.

Authors

Enoal Gesny, Eva Giboulot

Abstract

To comply with recent regulations requiring traceable generated content, modern watermarking has adopted multi-bit post-hoc watermarking schemes. These modern designs rest on an encoder-decoder pair implemented as deep neural networks. These models are usually treated as pure black-boxes trained end-to-end, with the noise of the watermarking channel modeled through a fixed set of geometric and valuemetric transforms applied to watermarked images. We argue that this purely empirical approach leads to unquestioned design flaws and a lack of theoretical performance guarantees. This work proposes a general theoretical model of modern post-hoc watermarking schemes grounded in a statistical analysis of the outputs of the encoder/decoder pair. We show that these deep neural networks implicitly define a watermarking channel modeled as parallel AWGN channels, with messages transmitted using BPSK modulation. This imposes a binary alphabet, greatly limiting the capacity of these watermarking systems. Another fatal flaw is their lack of a secret key, making them intrinsically insecure. We make this notion of watermarking security precise for post-hoc schemes by linking it to the possibility of estimating the secret key under a given statistical model of the decoder's output. By putting together the results from this theoretical analysis, we introduce SNW: a novel post-hoc watermarking system that significantly outperforms existing state-of-the-art baselines in terms of capacity while also providing strong security guarantees. Notably, it does not depend on a fixed codebook or binary alphabet, allowing it to reach a rate close to Shannon capacity through the use of capacity-achieving error-correcting codes.