为扩散模型分发设计安全高效水印,防泄露且抗攻击
Secure and Efficient Watermarking for Latent Diffusion Models in Model Distribution Scenarios
- 通过随机性与模型关联性约束强制嵌入水印
- 在10种攻击下仍保持高鲁棒性,优于6个基线方法
- 适合需版权保护的生成模型分发场景
潜在扩散模型在生成任务中展现出巨大潜力。水印被视为保护生成模型版权、防止滥用的替代方案。然而,在模型分发场景中,大规模用户访问带来安全、效率和鲁棒性的新挑战。为此,我们提出一种安全高效的水印方案。设计新型安全机制,防止水印泄露与逃逸,将水印随机性与水印-模型关联性作为强制嵌入的双重约束。为降低安全模块训练时间成本,将水印注入与安全机制解耦,仅微调VAE实现安全机制,无需学习水印模式。提出基于水印分发的验证策略,增强对多种攻击的鲁棒性。实验表明,该水印方案在10种图像处理与对抗攻击下,持续优于6个基线,在分发场景中显著提升安全性。
原文摘要 · Abstract (English)
Latent diffusion models have exhibited considerable potential in generative tasks. Watermarking is considered to be an alternative to safeguard the copyright of generative models and prevent their misuse. However, in the context of model distribution scenarios, the accessibility of models to large scale of model users brings new challenges to the security, efficiency and robustness of existing watermark solutions. To address these issues, we propose a secure and efficient watermarking solution. A new security mechanism is designed to prevent watermark leakage and watermark escape, which considers watermark randomness and watermark-model association as two constraints for mandatory watermark injection. To reduce the time cost of training the security module, watermark injection and the security mechanism are decoupled, ensuring that fine-tuning VAE only accomplishes the security mechanism without the burden of learning watermark patterns. A watermark distribution-based verification strategy is proposed to enhance the robustness against diverse attacks in the model distribution scenarios. Experimental results prove that our watermarking consistently outperforms existing six baselines on effectiveness and robustness against ten image processing attacks and adversarial attacks, while enhancing security in the distribution scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。