arXiv:2412.20704cs.CVcs.LG2024-12被引 12

无需训练即可检测扩散模型生成图像,还能隐式水印标记。

HFI: A unified framework for training-free detection and implicit watermarking of latent diffusion model generated images

  • 通过测量重建图像的混叠程度,捕捉高频信息失真。
  • 在简单背景图像上检测准确率提升显著,优于现有方法。
  • 适合需要无训练检测与隐式水印的AI内容安全场景。

潜空间扩散模型(LDM)在生成质量上的巨大进步也带来了恶意使用AI生成图像的问题。当前的检测方法通常依赖真实/生成图像进行训练,但在LDM表达能力极强的情况下,这一前提难以满足。因此,我们提出训练免费的检测框架——HFI。现有方法假设生成图像比真实图像更容易被自编码器重构,但该方法对背景信息过度拟合,导致在简单背景图像上表现不佳。为此,我们把LDM的自编码器视为一个下采样-上采样核,从重建图像中度量混叠(aliasing)程度,即高频信息的失真情况。该方法无需训练、高效且在多种生成模型产生的复杂图像上均显著优于其他训练免费方法。此外,我们证明了HFI可作为隐式水印技术,成功识别特定LDM生成的图像。其性能远超最优基线方法,且计算开销极小。

原文摘要 · Abstract (English)

Dramatic advances in the quality of the latent diffusion models (LDMs) also led to the malicious use of AI-generated images. While current AI-generated image detection methods assume the availability of real/AI-generated images for training, this is practically limited given the vast expressibility of LDMs. This motivates the training-free detection setup where no related data are available in advance. The existing LDM-generated image detection method assumes that images generated by LDM are easier to reconstruct using an autoencoder than real images. However, we observe that this reconstruction distance is overfitted to background information, leading the current method to underperform in detecting images with simple backgrounds. To address this, we propose a novel method called HFI. Specifically, by viewing the autoencoder of LDM as a downsampling-upsampling kernel, HFI measures the extent of aliasing, a distortion of high-frequency information that appears in the reconstructed image. HFI is training-free, efficient, and consistently outperforms other training-free methods in detecting challenging images generated by various generative models. We also show that HFI can successfully detect the images generated from the specified LDM as a means of implicit watermarking. HFI outperforms the best baseline method while achieving magnitudes of

图像检测隐式水印扩散模型无训练

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。