arXiv:2501.00463cs.LGcs.CR2025-01被引 2

通过自增强训练实现扩散模型图像水印的强泛化与无损质量

SAT-LDM: Provably Generalizable Image Watermarking for Latent Diffusion Models with Self-Augmented Training

  • 利用自由生成分布对齐训练与推理,提升水印泛化能力
  • 在多种提示下保持水印鲁棒性,且不引入可见伪影
  • 理论证明其泛化界限紧致,适合高保真内容版权保护

AI生成图像的快速普及催生了保护知识产权和检测伪造内容的有效水印技术需求。现有基于训练的水印方法虽具潜力,但跨不同提示的泛化能力弱,常引入可见伪影。为此,我们提出一种新型、可证明泛化的潜空间扩散模型图像水印方法——自增强训练(SAT-LDM)。该方法通过自由生成分布对齐训练与测试阶段,增强水印模块的泛化能力。我们从理论上证明,该自由生成分布有助于获得紧致的泛化界,无需额外数据收集。大量实验表明,SAT-LDM不仅实现鲁棒水印,还在广泛提示下显著提升水印图像质量。实验分析进一步验证了其强大的泛化性能。本方法为高保真AI生成内容的安全防护提供了实用高效的解决方案。

原文摘要 · Abstract (English)

The rapid proliferation of AI-generated images necessitates effective watermarking techniques to protect intellectual property and detect fraudulent content. While existing training-based watermarking methods show promise, they often struggle with generalizing across diverse prompts and tend to introduce visible artifacts. To this end, we propose a novel, provably generalizable image watermarking approach for Latent Diffusion Models, termed Self-Augmented Training (SAT-LDM). Our method aligns the training and testing phases through a free generation distribution, thereby enhancing the watermarking module's generalization capabilities. We theoretically consolidate SAT-LDM by proving that the free generation distribution contributes to its tight generalization bound, without the need for additional data collection. Extensive experiments show that SAT-LDM not only achieves robust watermarking but also significantly improves the quality of watermarked images across a wide range of prompts. Moreover, our experimental analyses confirm the strong generalization abilities of SAT-LDM. We hope that our method provides a practical and efficient solution for securing high-fidelity AI-generated content.

图像水印扩散模型泛化能力版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。