English

FDDWAN: A Frequency-Decoupled Diffusion Network for Watermarking Attack

Computer Vision and Pattern Recognition 2026-07-30 v1

Abstract

Existing invisible watermark removal methods often struggle to accurately capture the watermark-bearing features, leading to an unfavorable trade-off between watermark suppression and perceptual fidelity. In this paper, we propose the Frequency-Decoupled Diffusion Watermark Attack Network (FDDWAN), a coarse-to-fine framework that performs watermark removal through wavelet-domain decomposition and residual diffusion refinement. In the initial stage, the Wavelet-based Frequency-domain Preliminary Attack Module (WFPAM) decomposes the watermarked image into low- and high-frequency subbands and applies frequency-specific attack strategies tailored to their respective contributions to watermark robustness and perceptual quality. In the next stage, the Frequency-domain Residual Diffusion Attack Module (FRDAM) separately models the residual distributions between the preliminarily attacked outputs and the corresponding watermark-free references during training. Rather than reconstructing the entire image, FRDAM selectively refines frequency-domain residuals, directing the diffusion process toward the remaining watermark related discrepancies while minimizing modifications to image content. Extensive experiments on CelebA and ImageNet across four representative watermarking schemes demonstrate that FDDWAN achieves a more favorable trade-off between watermark removal effectiveness and visual fidelity than conventional and learning-based attack methods.

Cite

@article{arxiv.2607.27800,
  title  = {FDDWAN: A Frequency-Decoupled Diffusion Network for Watermarking Attack},
  author = {Chunpeng Wang and Yuxin Li and Xiaoyu Wang and Jidong Yang and Suo Gao and Qi Li},
  journal= {arXiv preprint arXiv:2607.27800},
  year   = {2026}
}