arXiv:2503.11195cs.CV2025-03被引 7

用哈希+加密+检测模型,让AI生成图难逃溯源追踪

Provenance Detection for AI-Generated Images: Combining Perceptual Hashing, Homomorphic Encryption, and AI Detection Models

  • 基于DINOV2改进感知哈希DinoHash,抗压缩滤镜等变换
  • 哈希准确率提升12%,检测模型识别率提高25%
  • 兼顾隐私保护与真实图像鉴别,适合内容监管场景

随着AI生成敏感图像日益增多,识别其来源对区分真实图像至关重要。传统水印方法易受滤镜、有损压缩和截图等常见操作破坏,且在模型开源或泄露时可能被伪造或移除。为此,我们提出一种三阶段安全、抗变换的AI内容溯源框架。首先,基于DINOV2构建对抗鲁棒的先进感知哈希模型DinoHash,可有效抵抗滤镜、压缩、裁剪等常见变换。其次,集成多方全同态加密(MP-FHE)方案,保障用户查询与注册信息隐私。此外,改进现有AI生成媒体检测方法,在无注册记录情况下仍可有效识别。实验表明,DinoHash在平均比特准确率上比现有水印与感知哈希方法高出12%,且在各类变换下保持优异真阳性率(TPR)与假阳性率(FPR)平衡。在主流真实世界AI图像生成器上的分类准确率较现有算法提升25%。结合感知哈希、MP-FHE与AI检测模型,本框架在鲁棒性与隐私保护方面优于以往工作。

原文摘要 · Abstract (English)

As AI-generated sensitive images become more prevalent, identifying their source is crucial for distinguishing them from real images. Conventional image watermarking methods are vulnerable to common transformations like filters, lossy compression, and screenshots, often applied during social media sharing. Watermarks can also be faked or removed if models are open-sourced or leaked since images can be rewatermarked. We have developed a three-part framework for secure, transformation-resilient AI content provenance detection, to address these limitations. We develop an adversarially robust state-of-the-art perceptual hashing model, DinoHash, derived from DINOV2, which is robust to common transformations like filters, compression, and crops. Additionally, we integrate a Multi-Party Fully Homomorphic Encryption~(MP-FHE) scheme into our proposed framework to ensure the protection of both user queries and registry privacy. Furthermore, we improve previous work on AI-generated media detection. This approach is useful in cases where the content is absent from our registry. DinoHash significantly improves average bit accuracy by 12% over state-of-the-art watermarking and perceptual hashing methods while maintaining superior true positive rate (TPR) and false positive rate (FPR) tradeoffs across various transformations. Our AI-generated media detection results show a 25% improvement in classification accuracy on commonly used real-world AI image generators over existing algorithms. By combining perceptual hashing, MP-FHE, and an AI content detection model, our proposed framework provides better robustness and privacy compared to previous work.

AI溯源感知哈希隐私保护图像检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。