arXiv:2411.03862cs.CVcs.AI2024-11NeurIPS被引 68

用对抗优化让扩散模型水印又隐又强,抗篡改能力提升。

ROBIN: Robust and Invisible Watermarks for Diffusion Models with Adversarial Optimization

  • 在扩散中间态嵌入水印,通过对抗优化主动隐藏
  • 水印在图像篡改后仍可验证,隐蔽性优于现有方法
  • 适合需要版权保护的生成式AI应用

生成内容水印是认证、版权保护和防范滥用的重要手段。现有方法难以兼顾鲁棒性与隐蔽性,通常通过限制水印强度被动实现隐蔽,从而削弱鲁棒性。本文提出ROBIN,显式引入水印隐藏过程,主动实现隐蔽性,允许嵌入更强水印。具体而言,在扩散模型的中间状态植入鲁棒水印,并通过对抗优化算法为每条水印生成最优隐藏提示信号。提示嵌入被优化以最小化生成图像中的伪影,同时水印本身被优化以达到最大强度。可通过逆向生成过程验证水印。在多种扩散模型上的实验表明,即使在显著图像篡改下,水印仍可验证,且隐蔽性优于其他先进鲁棒水印方法。代码已开源。

原文摘要 · Abstract (English)

Watermarking generative content serves as a vital tool for authentication, ownership protection, and mitigation of potential misuse. Existing watermarking methods face the challenge of balancing robustness and concealment. They empirically inject a watermark that is both invisible and robust and passively achieve concealment by limiting the strength of the watermark, thus reducing the robustness. In this paper, we propose to explicitly introduce a watermark hiding process to actively achieve concealment, thus allowing the embedding of stronger watermarks. To be specific, we implant a robust watermark in an intermediate diffusion state and then guide the model to hide the watermark in the final generated image. We employ an adversarial optimization algorithm to produce the optimal hiding prompt guiding signal for each watermark. The prompt embedding is optimized to minimize artifacts in the generated image, while the watermark is optimized to achieve maximum strength. The watermark can be verified by reversing the generation process. Experiments on various diffusion models demonstrate the watermark remains verifiable even under significant image tampering and shows superior invisibility compared to other state-of-the-art robust watermarking methods. Code is available at https://github.com/Hannah1102/ROBIN.

水印技术扩散模型版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。