攻击者可伪造或移除扩散模型的语义水印,无需原模型。
Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models
- 用无关模型操控潜在表示,将目标水印嵌入真实图像。
- 仅需一张带水印参考图,即可生成带指定水印的新图像。
- 揭示语义水印在真实场景下极易被伪造或删除。
将水印集成到潜在扩散模型(LDM)的生成过程中,可简化生成内容的检测与归属。语义水印(如 Tree-Rings、Gaussian Shading)是一类易于实现且对多种扰动具有高鲁棒性的新型水印技术。然而,本文揭示了语义水印的根本性安全漏洞。我们证明攻击者可利用无关模型(即使潜在空间与架构不同,如 UNet vs DiT)执行强大而逼真的伪造攻击。具体设计两种攻击:第一种通过操纵任意图像在无关 LDM 中的潜在表示,使其逼近带水印图像的潜在表示,从而将目标水印嵌入真实图像;该方法亦可用于水印移除。第二种攻击通过反演带水印图像并使用任意提示重新生成,生成带有目标水印的新图像。两种攻击均只需一张带目标水印的参考图像。总体而言,研究结果质疑了语义水印的实际适用性,揭示其在现实条件下易被轻易伪造或移除。
原文摘要 · Abstract (English)
Integrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. Specifically, we design two watermark forgery attacks. The first imprints a targeted watermark into real images by manipulating the latent representation of an arbitrary image in an unrelated LDM to get closer to the latent representation of a watermarked image. We also show that this technique can be used for watermark removal. The second attack generates new images with the target watermark by inverting a watermarked image and re-generating it with an arbitrary prompt. Both attacks just need a single reference image with the target watermark. Overall, our findings question the applicability of semantic watermarks by revealing that attackers can easily forge or remove these watermarks under realistic conditions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。