arXiv:2410.22445cs.CVcs.CR2024-10被引 1

将水印嵌入扩散过程全程,保护模型版权且不改变输出结果。

Embedding Watermarks in Diffusion Process for Model Intellectual Property Protection

  • 在扩散过程各阶段嵌入水印,而非仅末尾或通过后门
  • 理论证明最终输出不含额外信息,保持原生生成质量
  • 无需触发条件即可从内部样本验证水印,适合版权确权

实际应用中,扩散模型的广泛部署需大量训练投入。随着应用场景增多,模型滥用风险上升,亟需强健的知识产权保护。现有方法要么采用后门机制,将水印作为简化训练目标,易被现有防御手段破解;要么直接在生成样本中嵌入水印,根本性改变输出分布。本文提出一种新水印框架,将水印嵌入整个扩散过程,并理论上保证最终输出样本不包含额外信息。此外,我们利用统计算法从模型内部生成样本中无须触发条件即可验证水印。详细理论分析与实验验证表明该方法有效。

原文摘要 · Abstract (English)

In practical application, the widespread deployment of diffusion models often necessitates substantial investment in training. As diffusion models find increasingly diverse applications, concerns about potential misuse highlight the imperative for robust intellectual property protection. Current protection strategies either employ backdoor-based methods, integrating a watermark task as a simpler training objective with the main model task, or embedding watermarks directly into the final output samples. However, the former approach is fragile compared to existing backdoor defense techniques, while the latter fundamentally alters the expected output. In this work, we introduce a novel watermarking framework by embedding the watermark into the whole diffusion process, and theoretically ensure that our final output samples contain no additional information. Furthermore, we utilize statistical algorithms to verify the watermark from internally generated model samples without necessitating triggers as conditions. Detailed theoretical analysis and experimental validation demonstrate the effectiveness of our proposed method.

扩散模型水印技术版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。