在生成3D神经辐射场时植入水印,防抄袭且不降质量。
DreaMark: Rooting Watermark in Score Distillation Sampling Generated Neural Radiance Fields
- 生成时直接植入后门水印,无需事后微调。
- 水印在图像和模型攻击下仍保持90%以上识别准确率。
- 适合需版权保护的3D内容创作者使用。
文本到3D生成技术可利用分数蒸馏采样(Score Distillation Sampling)生成神经辐射场(NeRF),实现无需真实数据采集的3D资产创建。随着NeRF生成质量快速提升,保护其版权日益重要。现有方法多为生成后嵌入水印,存在两个缺陷:一是生成与水印之间有延迟,因需通过微调嵌入秘密信息;二是生成非水印版本作为中间产物,易被窃取。为此,我们提出Dreamark,在生成过程中直接植入水印。具体地,先预训练水印解码器,再生成带有后门的NeRF,使目标秘密信息可通过预训练解码器在任意触发视图上验证。实验评估了生成质量与水印对图像级和模型级攻击的鲁棒性。结果表明,水印过程不影响生成质量,且在高斯噪声等图像级攻击和剪枝等模型级攻击下,水印识别准确率均超过90%。
原文摘要 · Abstract (English)
Recent advancements in text-to-3D generation can generate neural radiance fields (NeRFs) with score distillation sampling, enabling 3D asset creation without real-world data capture. With the rapid advancement in NeRF generation quality, protecting the copyright of the generated NeRF has become increasingly important. While prior works can watermark NeRFs in a post-generation way, they suffer from two vulnerabilities. First, a delay lies between NeRF generation and watermarking because the secret message is embedded into the NeRF model post-generation through fine-tuning. Second, generating a non-watermarked NeRF as an intermediate creates a potential vulnerability for theft. To address both issues, we propose Dreamark to embed a secret message by backdooring the NeRF during NeRF generation. In detail, we first pre-train a watermark decoder. Then, the Dreamark generates backdoored NeRFs in a way that the target secret message can be verified by the pre-trained watermark decoder on an arbitrary trigger viewport. We evaluate the generation quality and watermark robustness against image- and model-level attacks. Extensive experiments show that the watermarking process will not degrade the generation quality, and the watermark achieves 90+% accuracy among both image-level attacks (e.g., Gaussian noise) and model-level attacks (e.g., pruning attack).
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。