IRAW: Novel invisible and robust adversarial watermark perturbations for digital image protection.
basic_science · Level V
Where this comes from
- Record sourced from PubMed, PMID 42013631.
- Also identified by DOI 10.1016/j.neunet.2026.109011.
- No licence information is recorded for this record.
- Because redistribution is not established, this page shows the abstract only. Follow the links below for the full text.
Abstract
Invisible watermarking has long been a cornerstone for copyright protection due to its imperceptibility and forensic traceability. However, traditional watermarking remains a passive defense that fails to preclude unauthorized AI-driven analysis, such as the automated categorization and indexing of private media by illicit scrapers. To address this, we propose invisible and robust adversarial watermarking (IRAW), a unified framework that transitions image protection from passive traceability to proactive defense. By leveraging the discrete cosine transform (DCT) domain, IRAW ensures native compatibility with the JPEG compression protocols prevalent on mainstream social media platforms. The framework treats watermark embedding and adversarial perturbation generation as a synergistic optimization task. Specifically, an evolutionary optimization mechanism based on the integration of basin hopping (BH) with crossover and adaptive mutation operators is employed to navigate the search space and identify optimal perturbation patterns. To further enhance security, we implement a cross-domain defense architecture featuring dual spatial-domain encryption for host images and watermarks, combined with frequency-domain coordinate obfuscation. This mechanism not only bolsters cryptographic strength but also increases the structural complexity of perturbations, assisting the BH algorithm in escaping local optima to improve perturbation success rates. Experimental results demonstrate that IRAW generates high-fidelity adversarial examples with exceptional robustness against common image operations, such as JPEG compression and noise, while enabling reliable watermark recovery for forensic provenance. These findings establish IRAW as an effective and industrially compatible mechanism for modern digital image protection.