arXiv:2410.21669cs.CV2024-10中稿 · ICLR被引 4

发现视频生成模型会记忆训练数据,可能泄露版权内容。

Investigating Memorization in Video Diffusion Models

  • 区分内容与运动两类记忆,提出针对性评估方法。
  • 从多个开源模型中成功提取出大量训练视频数据。
  • 适合关注生成模型隐私安全的研究者与开发者。

扩散模型广泛用于图像和视频生成,但存在推理时记忆并重现训练数据的风险,可能导致未经授权的版权内容生成。尽管先前研究集中于图像扩散模型(IDMs),视频扩散模型(VDMs)仍缺乏深入探索。为此,我们首次以实用方式明确定义了VDMs中的两类记忆(内容记忆与运动记忆),聚焦隐私保护且适用于所有生成类型。随后,我们设计了专门用于分离评估内容与运动记忆的新指标,并构建了一个易触发记忆的文本提示数据集。利用这些提示,我们在多个开源VDM上生成多样视频,成功从每个测试模型中提取出大量训练视频。通过应用所提指标,我们系统分析了多种预训练VDM在不同数据集上的记忆现象。结果表明,记忆现象普遍存在于所有测试的VDM中,说明它们不仅能记忆视频数据,还能记忆图像训练数据。最后,我们提出了高效有效的内容与运动记忆检测策略,为提升VDM隐私性提供基础方案。

原文摘要 · Abstract (English)

Diffusion models, widely used for image and video generation, face a significant limitation: the risk of memorizing and reproducing training data during inference, potentially generating unauthorized copyrighted content. While prior research has focused on image diffusion models (IDMs), video diffusion models (VDMs) remain underexplored. To address this gap, we first formally define the two types of memorization in VDMs (content memorization and motion memorization) in a practical way that focuses on privacy preservation and applies to all generation types. We then introduce new metrics specifically designed to separately assess content and motion memorization in VDMs. Additionally, we curate a dataset of text prompts that are most prone to triggering memorization when used as conditioning in VDMs. By leveraging these prompts, we generate diverse videos from various open-source VDMs, successfully extracting numerous training videos from each tested model. Through the application of our proposed metrics, we systematically analyze memorization across various pretrained VDMs, including text-conditional and unconditional models, on a variety of datasets. Our comprehensive study reveals that memorization is widespread across all tested VDMs, indicating that VDMs can also memorize image training data in addition to video datasets. Finally, we propose efficient and effective detection strategies for both content and motion memorization, offering a foundational approach for improving privacy in VDMs.

视频生成扩散模型隐私安全记忆检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。