arXiv:2410.07369cs.CRcs.AI2024-10被引 103

用伪随机纠错码在生成图像中嵌入不可检测的水印,既保真又抗删。

An Undetectable Watermark for Generative Image Models

  • 通过伪随机纠错码控制扩散模型初始隐变量实现水印
  • 水印不降质且可编码512比特(抗删除时达2500比特)
  • 对现有移除攻击鲁棒,适合版权保护场景

我们提出首个不可检测的生成图像模型水印方案。不可检测性确保任何高效攻击者都无法通过大量自适应查询区分带水印与无水印图像。特别地,该水印在任意高效可计算度量下均不降低图像质量。方案通过使用伪随机纠错码(Christ and Gunn, 2024)选择扩散模型的初始隐变量,保证了不可检测性和鲁棒性。实验验证,在Stable Diffusion 2.1上,本水印保持图像质量且具备鲁棒性:相比所有测试过的先前方案,本方法不降低图像质量;现有水印移除攻击无法在不显著损害图像质量的前提下移除水印。最终,我们可稳健编码512比特水印信息,若无需抵抗移除攻击,则最多可编码2500比特。代码已开源:https://github.com/XuandongZhao/PRC-Watermark。

原文摘要 · Abstract (English)

We present the first undetectable watermarking scheme for generative image models. Undetectability ensures that no efficient adversary can distinguish between watermarked and un-watermarked images, even after making many adaptive queries. In particular, an undetectable watermark does not degrade image quality under any efficiently computable metric. Our scheme works by selecting the initial latents of a diffusion model using a pseudorandom error-correcting code (Christ and Gunn, 2024), a strategy which guarantees undetectability and robustness. We experimentally demonstrate that our watermarks are quality-preserving and robust using Stable Diffusion 2.1. Our experiments verify that, in contrast to every prior scheme we tested, our watermark does not degrade image quality. Our experiments also demonstrate robustness: existing watermark removal attacks fail to remove our watermark from images without significantly degrading the quality of the images. Finally, we find that we can robustly encode 512 bits in our watermark, and up to 2500 bits when the images are not subjected to watermark removal attacks. Our code is available at https://github.com/XuandongZhao/PRC-Watermark.

图像水印生成模型隐私保护扩散模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。