arXiv:2410.21653cs.CV2024-10被引 1

SISR模型生成图像也留有独特指纹,可用来识别模型或反推参数。

Fingerprints of Super Resolution Networks

  • 通过分析SISR输出图像的细微特征提取模型指纹。
  • 高倍超分或使用对抗损失的模型指纹更明显。
  • 适合研究模型溯源、版权保护的从业者参考。

近期研究表明,基于深度学习的图像生成模型(如GAN)可在其输出图像中留下可识别的指纹,甚至可被逆向工程。本文将该研究扩展至单图像超分辨率(SISR)网络。与以往模型相比,SISR模型生成的图像常接近真实图像,难以嵌入显著特征,因而提取指纹更具挑战性。我们以SISR模型为例,验证此前关于GAN指纹的发现是否适用于通用图像生成模型。结果表明,具有高上采样因子或采用对抗损失训练的SISR模型会产生高度独特的指纹;在特定条件下,部分超参数可通过这些指纹被逆向推导。

原文摘要 · Abstract (English)

Several recent studies have demonstrated that deep-learning based image generation models, such as GANs, can be uniquely identified, and possibly even reverse-engineered, by the fingerprints they leave on their output images. We extend this research to single image super-resolution (SISR) networks. Compared to previously studied models, SISR networks are a uniquely challenging class of image generation model from which to extract and analyze fingerprints, as they can often generate images that closely match the corresponding ground truth and thus likely leave little flexibility to embed signatures. We take SISR models as examples to investigate if the findings from the previous work on fingerprints of GAN-based networks are valid for general image generation models. We show that SISR networks with a high upscaling factor or trained using adversarial loss leave highly distinctive fingerprints, and that under certain conditions, some SISR network hyperparameters can be reverse-engineered from these fingerprints.

超分辨率模型指纹逆向工程

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。