arXiv:2411.07449cs.CV2024-11NeurIPS被引 1

通过分析扩散过程的时间动态,精准判断图像来源,打破传统认知局限。

Tracing the Roots: Leveraging Temporal Dynamics in Diffusion Trajectories for Origin Attribution

  • 利用整个去噪轨迹的时序特征进行来源识别
  • 实验证明现有方法在分布偏移下失效,且不依赖特定去噪阶段
  • 首次实现对扩散模型生成内容的白盒溯源,适合安全与版权检测

扩散模型通过迭代去噪实现了图像生成的突破,但其负责任使用的关键问题仍未解决:如何验证一张图像是否源自模型训练集、模型生成结果或外部来源。本文提出一种基于扩散轨迹时序动态的溯源框架。研究表明,全轨迹的时间动态可提升分类鲁棒性,挑战了“黄金区域”假说——即仅在特定去噪阶段有效进行成员推理。更根本的是,本文揭示当前成员推理方法在分布偏移或存在模型生成数据时严重失效。针对模型溯源,本文首次提出可直接应用于扩散模型的白盒方法。最终,推动将数据溯源统一为适配现代生成系统的完整框架。

原文摘要 · Abstract (English)

Diffusion models have transformed image synthesis through iterative denoising, by defining trajectories from noise to coherent data. While their capabilities are widely celebrated, a critical challenge remains unaddressed: ensuring responsible use by verifying whether an image originates from a model's training set, its novel generations or external sources. We introduce a framework that analyzes diffusion trajectories for this purpose. Specifically, we demonstrate that temporal dynamics across the entire trajectory allow for more robust classification and challenge the widely-adopted "Goldilocks zone" conjecture, which posits that membership inference is effective only within narrow denoising stages. More fundamentally, we expose critical flaws in current membership inference practices by showing that representative methods fail under distribution shifts or when model-generated data is present. For model attribution, we demonstrate a first white-box approach directly applicable to diffusion. Ultimately, we propose the unification of data provenance into a single, cohesive framework tailored to modern generative systems.

扩散模型溯源生成安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。