将水印嵌入扩散模型本身,实现不可见且可精准提取的版权保护。
Image Watermarking of Generative Diffusion Models
- 在模型训练时直接嵌入水印特征,通过端到端学习同步训练提取器。
- 水印在图像中几乎不可见,检测准确率高,支持多水印区分。
- 适合需要版权验证的生成式模型应用,如艺术创作与内容溯源。
将水印嵌入生成模型的输出对于建立版权和可验证的所有权至关重要。现有扩散模型水印方法要么在频域嵌入,要么在图像空间中水印模式灵活性不足,导致水印容易被简单检测或移除。为此,我们提出一种将水印特征嵌入扩散模型自身的技术。该方法可端到端训练配套的水印提取器,迫使生成器在训练过程中有效嵌入多样且不可察觉的水印,同时确保其精确恢复。实验表明,该方法实现了高精度的水印嵌入与检测,并能区分不同模型所嵌入的水印,从而实现生成模型的身份识别。
原文摘要 · Abstract (English)
Embedding watermarks into the output of generative models is essential for establishing copyright and verifiable ownership over the generated content. Emerging diffusion model watermarking methods either embed watermarks in the frequency domain or offer limited versatility of the watermark patterns in the image space, which allows simplistic detection and removal of the watermarks from the generated content. To address this issue, we propose a watermarking technique that embeds watermark features into the diffusion model itself. Our technique enables training of a paired watermark extractor for a generative model that is learned through an end-to-end process. The extractor forces the generator, during training, to effectively embed versatile, imperceptible watermarks in the generated content while simultaneously ensuring their precise recovery. We demonstrate highly accurate watermark embedding/detection and show that it is also possible to distinguish between different watermarks embedded with our method to differentiate between generative models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。