acceptodds
Under review as a conference paper at ICLR 2027

From Fixed JND to Learned Attenuation in Invisible Image Watermarking

Abstract

In invisible image watermarking, the attenuation map sets the per-pixel strength of the watermark residual. We ask whether replacing fixed just-noticeable-difference (JND) attenuation with a learned attenuation map improves the quality-robustness trade-off, and whether any robustness gain survives when the embedded distortion, rather than the embedding coefficient, is held fixed. Freezing Pixel Seal's embedder and extractor, we train a U-Net that predicts the attenuation map. At the same coefficient, the base learned map raises bit accuracy under a combined JPEG-crop-brightness attack by 3.81 percentage points (pp) but lowers PSNR by 5.37 dB; adding an LPIPS loss and Shape-Aligned Attenuation (SAA), which aligns the mean-normalized learned and JND maps, recovers 2.05 dB at a 0.31 pp accuracy cost. At matched PSNR, however, this advantage disappears: fixed JND takes a small but significant lead (0.36-0.38 pp over the best learned condition at all but the highest target), and among the learned conditions the robustness differences come from SAA (+0.55-2.59 pp, with or without the LPIPS loss). The learned conditions' lower LPIPS at matched PSNR also largely vanishes at matched robustness, where fixed JND needs the least distortion. In exploratory tests on MaskWM, WAM, and VideoSeal, matching PSNR likewise narrows the JPEG-attack gap to under 1.2 pp (learned attenuation stays slightly ahead on VideoSeal). With Pixel Seal's backbone frozen, learned attenuation therefore improves on fixed JND neither in robustness at equal distortion nor clearly in quality at equal robustness, and single-coefficient comparisons overstate its benefit.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.