arXiv:2411.13144cs.CRcs.AI2024-11被引 9

构建统一评估框架,系统测试图像生成模型版权保护效果

CopyrightMeter: Revisiting Copyright Protection in Text-to-image Models

  • 提出CopyrightMeter框架,整合17种保护与16种攻击方法
  • 发现16/17种保护方法在攻击下失效,效果随目标优先级变化
  • 为版权保护研究提供可复现的基准评测标准,适合安全与合规研究者

文本到图像扩散模型虽能生成高质量图像,但其滥用可能导致未经授权的内容复制,引发版权问题。已有防护方法如对抗扰动、概念擦除和水印技术,但其有效性与鲁棒性尚未充分验证,且缺乏统一评估框架。为此,本文系统梳理现有防护方法与攻击手段,构建统一分类体系,并开发CopyrightMeter评估框架,集成17种先进防护与16种典型攻击。通过多维度实验发现:(i)16/17种防护在攻击下均不具鲁棒性;(ii)最优防护方案取决于具体保护目标;(iii)更高级攻击推动防护技术持续演进。研究成果为设计更稳健的版权保护机制提供依据,其评估协议也为未来研究建立标准化基准。

原文摘要 · Abstract (English)

Text-to-image diffusion models have emerged as powerful tools for generating high-quality images from textual descriptions. However, their increasing popularity has raised significant copyright concerns, as these models can be misused to reproduce copyrighted content without authorization. In response, recent studies have proposed various copyright protection methods, including adversarial perturbation, concept erasure, and watermarking techniques. However, their effectiveness and robustness against advanced attacks remain largely unexplored. Moreover, the lack of unified evaluation frameworks has hindered systematic comparison and fair assessment of different approaches. To bridge this gap, we systematize existing copyright protection methods and attacks, providing a unified taxonomy of their design spaces. We then develop CopyrightMeter, a unified evaluation framework that incorporates 17 state-of-the-art protections and 16 representative attacks. Leveraging CopyrightMeter, we comprehensively evaluate protection methods across multiple dimensions, thereby uncovering how different design choices impact fidelity, efficacy, and resilience under attacks. Our analysis reveals several key findings: (i) most protections (16/17) are not resilient against attacks; (ii) the "best" protection varies depending on the target priority; (iii) more advanced attacks significantly promote the upgrading of protections. These insights provide concrete guidance for developing more robust protection methods, while its unified evaluation protocol establishes a standard benchmark for future copyright protection research in text-to-image generation.

版权保护图像生成评估框架扩散模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。