通过扩散模型的低维子空间实现隐蔽且鲁棒的水印嵌入
Shallow Diffuse: Robust and Invisible Watermarking through Low-Dimensional Subspaces in Diffusion Models
- 利用生成过程中的低维子空间分离水印信号
- 水印在图像生成中保持一致且可检测,抗干扰能力强
- 适合需要版权保护的AI图像生成场景
扩散模型生成的AI内容泛滥,引发虚假信息与版权侵权担忧。水印技术是识别此类图像、防止滥用的关键手段。本文提出Shallow Diffuse,一种在扩散模型输出中嵌入隐蔽且鲁棒水印的新方法。不同于传统在完整采样过程中嵌入水印的方式,Shallow Diffuse通过利用图像生成过程中的低维子空间特性,将水印主要置于该子空间的零空间中,从而实现水印与生成过程的有效解耦。理论与实证分析表明,这种解耦策略显著提升了生成一致性与水印可检测性。大量实验验证,Shallow Diffuse在鲁棒性与一致性方面均优于现有方法。代码已开源:https://github.com/liwd190019/Shallow-Diffuse。
原文摘要 · Abstract (English)
The widespread use of AI-generated content from diffusion models has raised significant concerns regarding misinformation and copyright infringement. Watermarking is a crucial technique for identifying these AI-generated images and preventing their misuse. In this paper, we introduce Shallow Diffuse, a new watermarking technique that embeds robust and invisible watermarks into diffusion model outputs. Unlike existing approaches that integrate watermarking throughout the entire diffusion sampling process, Shallow Diffuse decouples these steps by leveraging the presence of a low-dimensional subspace in the image generation process. This method ensures that a substantial portion of the watermark lies in the null space of this subspace, effectively separating it from the image generation process. Our theoretical and empirical analyses show that this decoupling strategy greatly enhances the consistency of data generation and the detectability of the watermark. Extensive experiments further validate that our Shallow Diffuse outperforms existing watermarking methods in terms of robustness and consistency. The codes are released at https://github.com/liwd190019/Shallow-Diffuse.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。