Compositional Adversarial Training for Robust Visual Watermarking
Abstract
Robust watermarking is typically trained with random post-processing augmentation, but random sampling under-covers the combinatorial space of realistic attack pipelines and rarely encounters the rare compositions that actually break detection. This leads to unstable training and poor sample efficiency. We instead formulate watermark robustness as a min-max problem over a structured space of compositional transformations. We propose Compositional Adversarial Training (CAT), a plug-in framework that learns a sequential differentiable adversary that observes the current intermediate image and adaptively selects an attack family at each step to maximally disrupt message recovery. CAT combines a straight-through Gumbel-Softmax attack selection with entropy regularization, allowing the backward pass to be end-to-end differentiable and aggregate gradient information across attack families, yielding faster, smoother convergence without collapsing to a single attack mode. We evaluate CAT on post-generation watermarks VideoSeal 0.0, VideoSeal 1.0, and PixelSeal and in-generation WMAR under both single-step and two-step attack suites, on in-distribution and multiple out-of-distribution image and video benchmarks. CAT consistently outperforms random-augmentation baselines trained for the same number of gradient updates and the same augmentation budget, with the largest gains on hard composed attacks and OOD evaluations; in the SA-1B and CLIC image benchmarks, it improves overall watermark capacity by up to 74.3% in the single-step setting and 24.2% in the compositional setting. In the autoregressive setting, CAT raises difficult geometric TPR@FPR by up to 18 percentage points. These results show that robust visual watermarking benefits from training against adaptive compositional adversaries rather than independent random corruptions.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.