AdMarks: Image Steganography Based on Adversarial Perturbation
摘要
Steganography methods (a.k.a. watermarks) embed specific information into multimedia carriers for the protection of copyrights. However, conventional methods such as Least Significant Bit (LSB) and frequency domain transformation are vulnerable to tampering attacks. Thus, the resulting watermarks cannot be easily traced after release to the public. We address this problem by exploiting adversarial perturbations in a positive way. The proposed AdMarks system embeds adversarial perturbations generated on object detection models and encodes the “detection errors” as watermarks. Our evaluations on real-life datasets show that the proposed watermarks are barely visible by human eyes and robust under image transformations such as cropping and JPEG compression. In particular, AdMarks can generate unlimited digital watermarks on single image that ensures the uniqueness and traceability on each copy of the original media.