修复扩散模型语义水印中的密码学误用问题
Towards A Correct Usage of Cryptography in Semantic Watermarks for Diffusion Models
- 基于IND$-CPA安全提出全新无损性能证明
- 揭示原有方法在密钥管理上的漏洞
- 兼顾安全、效率与生成质量的配置建议
语义水印技术通过仅修改初始隐变量噪声,实现水印直接嵌入潜在扩散模型的生成过程。现有基于高斯着色的方法依赖密码学原语引导隐变量采样,但其在无损性能证明和密钥管理方面存在多处问题,导致后续研究产生歧义。本文重新审视语义水印中的密码学原语,提出一种新的通用无损性能证明,基于IND$-CPA安全性;同时探讨密码学原语在安全性、效率与生成质量之间的配置权衡。
原文摘要 · Abstract (English)
Semantic watermarking methods enable the direct integration of watermarks into the generation process of latent diffusion models by only modifying the initial latent noise. One line of approaches building on Gaussian Shading relies on cryptographic primitives to steer the sampling process of the latent noise. However, we identify several issues in the usage of cryptographic techniques in Gaussian Shading, particularly in its proof of lossless performance and key management, causing ambiguity in follow-up works, too. In this work, we therefore revisit the cryptographic primitives for semantic watermarking. We introduce a novel, general proof of lossless performance based on IND\$-CPA security for semantic watermarks. We then discuss the configuration of the cryptographic primitives in semantic watermarks with respect to security, efficiency, and generation quality.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。