arXiv:2502.07845cs.CVcs.AI2025-02被引 1

在生成图像中嵌入鲁棒水印,可追踪来源且无需重训练模型。

Spread them Apart: Towards Robust Watermarking of Generated Content

  • 推理时嵌入水印,不需重新训练生成模型。
  • 水印对有限幅度的加性扰动具有鲁棒性。
  • 适用于扩散模型,抗多种合成移除攻击,效果达顶尖水平。

近年来,生成模型在生成逼真图像方面取得了显著进步,生成内容的质量大幅提升,使得真实图像与生成图像之间的区分变得极为困难。这种进步带来了伦理问题:用户可能不当宣称对受版权保护的生成内容拥有所有权。本文提出一种方法,在生成内容中嵌入水印,以实现未来对生成内容的检测及生成者身份的识别。水印在模型推理阶段嵌入,无需重新训练模型。我们证明了嵌入的水印对有限幅度的加性扰动具有鲁棒性。我们将该方法应用于扩散模型,结果显示其在抵御多种合成水印移除攻击方面的鲁棒性达到当前最先进水平。

原文摘要 · Abstract (English)

Generative models that can produce realistic images have improved significantly in recent years. The quality of the generated content has increased drastically, so sometimes it is very difficult to distinguish between the real images and the generated ones. Such an improvement comes at a price of ethical concerns about the usage of the generative models: the users of generative models can improperly claim ownership of the generated content protected by a license. In this paper, we propose an approach to embed watermarks into the generated content to allow future detection of the generated content and identification of the user who generated it. The watermark is embedded during the inference of the model, so the proposed approach does not require the retraining of the latter. We prove that watermarks embedded are guaranteed to be robust against additive perturbations of a bounded magnitude. We apply our method to watermark diffusion models and show that it matches state-of-the-art watermarking schemes in terms of robustness to different types of synthetic watermark removal attacks.

水印技术生成模型扩散模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。