변조 방지 기능이 있는 다용도 워터마킹을 통한 고품질 얼굴 콘텐츠 복구
High-Fidelity Face Content Recovery via Tamper-Resilient Versatile Watermarking
AI 생성 콘텐츠(AIGC) 기반 얼굴 조작 및 딥페이크의 확산은 미디어의 출처, 무결성 및 저작권 보호에 심각한 위협을 초래합니다. 기존의 다용도 워터마킹 시스템은 일반적으로 명시적인 위치 정보 페이로드를 삽입하는데, 이는 충실도와 기능 간의 균형을 깨뜨립니다. 즉, 위치 정보 신호가 클수록 시각적 품질이 저하되고, 강력한 생성 편집 시 디코딩의 안정성이 떨어질 수 있습니다. 또한, 기존 방법은 콘텐츠 복구를 지원하지 않는 경우가 많아, 원본 증거를 복원해야 하는 상황에서 법의학적 가치가 제한됩니다. 이러한 문제점을 해결하기 위해, 우리는 저작권 보호, 픽셀 수준의 조작 위치 파악, 그리고 고품질 얼굴 콘텐츠 복구를 통합하는 다용도 워터마킹 프레임워크인 VeriFi를 제안합니다. VeriFi는 다음과 같은 세 가지 핵심적인 기여를 합니다. (1) 콘텐츠를 보존하는 우선 정보를 제공하는 압축된 의미론적 잠재 워터마크를 삽입하여, 심각한 조작 이후에도 충실한 복원을 가능하게 합니다. (2) 이미지 특징과 디코딩된 출처 신호를 연관시켜 위치 정보 관련 아티팩트를 삽입하지 않고도 정밀한 위치 파악을 달성합니다. (3) 잠재 공간 혼합과 매끄러운 블렌딩을 결합하여 현실적인 딥페이크 파이프라인에 대한 강건성을 향상시키는 AIGC 공격 시뮬레이터를 도입합니다. CelebA-HQ 및 FFHQ 데이터셋에 대한 광범위한 실험 결과, VeriFi는 워터마크 강건성, 위치 파악 정확도 및 복구 품질 측면에서 강력한 기존 방법보다 우수한 성능을 보이며, 딥페이크 법의학에 대한 실용적이고 검증 가능한 방어 솔루션을 제공합니다.
The proliferation of AIGC-driven face manipulation and deepfakes poses severe threats to media provenance, integrity, and copyright protection. Prior versatile watermarking systems typically rely on embedding explicit localization payloads, which introduces a fidelity--functionality trade-off: larger localization signals degrade visual quality and often reduce decoding robustness under strong generative edits. Moreover, existing methods rarely support content recovery, limiting their forensic value when original evidence must be reconstructed. To address these challenges, we present VeriFi, a versatile watermarking framework that unifies copyright protection, pixel-level manipulation localization, and high-fidelity face content recovery. VeriFi makes three key contributions: (1) it embeds a compact semantic latent watermark that serves as an content-preserving prior, enabling faithful restoration even after severe manipulations; (2) it achieves fine-grained localization without embedding localization-specific artifacts by correlating image features with decoded provenance signals; and (3) it introduces an AIGC attack simulator that combines latent-space mixing with seamless blending to improve robustness to realistic deepfake pipelines. Extensive experiments on CelebA-HQ and FFHQ show that VeriFi consistently outperforms strong baselines in watermark robustness, localization accuracy, and recovery quality, providing a practical and verifiable defense for deepfake forensics.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.