arXiv:2503.11071cs.CV2025-03CVPR被引 2

利用频谱特征保护图像版权,即使水印仅占1%数据也有效

Harnessing Frequency Spectrum Insights for Image Copyright Protection Against Diffusion Models

  • 通过分析扩散模型生成图像的频谱特性,发现其忠实保留训练数据统计特征
  • 提出CoprGuard框架,在1%水印数据下仍能有效识别未经授权使用
  • 适用于多种扩散模型,尤其适合内容创作者保护原创数字资产

扩散模型在新视角合成中取得显著进展,但其依赖大规模、多样且常难以追踪的网络数据集,引发图像版权保护的紧迫问题。现有方法难以可靠识别未经授权的图像使用,因在不同生成任务间泛化能力差,且当训练数据来自多个来源且仅有少量可识别(带水印或中毒)样本时失效。本文首次揭示扩散生成图像会忠实保留训练数据的统计特性,尤其体现在频谱特征上。基于此洞察,我们提出CoprGuard——一种鲁棒的频域水印框架,用于保护扩散模型训练与微调中的图像版权。CoprGuard在从基础扩散模型到复杂文本到图像模型的广泛模型上均表现优异,即便水印图像仅占训练数据1%,依然具备强鲁棒性。这一高效通用的方法使内容所有者能够在人工智能驱动的图像生成时代有效捍卫知识产权。

原文摘要 · Abstract (English)

Diffusion models have achieved remarkable success in novel view synthesis, but their reliance on large, diverse, and often untraceable Web datasets has raised pressing concerns about image copyright protection. Current methods fall short in reliably identifying unauthorized image use, as they struggle to generalize across varied generation tasks and fail when the training dataset includes images from multiple sources with few identifiable (watermarked or poisoned) samples. In this paper, we present novel evidence that diffusion-generated images faithfully preserve the statistical properties of their training data, particularly reflected in their spectral features. Leveraging this insight, we introduce \emph{CoprGuard}, a robust frequency domain watermarking framework to safeguard against unauthorized image usage in diffusion model training and fine-tuning. CoprGuard demonstrates remarkable effectiveness against a wide range of models, from naive diffusion models to sophisticated text-to-image models, and is robust even when watermarked images comprise a mere 1\% of the training dataset. This robust and versatile approach empowers content owners to protect their intellectual property in the era of AI-driven image generation.

图像版权扩散模型频谱分析水印技术

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。