arXiv:2503.23332cs.CV2025-03中稿 · Expert Systems wit…被引 1

用随机变量重排实现不可见水印,让生成图可溯源且不降质。

TraceMark-LDM: Authenticatable Watermarking for Latent Diffusion Models via Binary-Guided Rearrangement

  • 用水印引导高斯采样变量重排,避免直接修改图像
  • 在多种攻击下仍保持95%以上水印识别率
  • 适合需要版权保护的AI图像生成场景

图像生成技术日益融入社会各领域,但缺乏有效监管易导致恶意内容传播和版权侵权。当前主流的文生图模型——潜空间扩散模型(LDM)虽广泛应用,但现有溯源方法多直接在图像或中间噪声中嵌入水印,损害生成质量与鲁棒性。为此,本文提出TraceMark-LDM,通过水印作为引导对高斯分布采样的随机变量进行重排,实现非破坏性溯源。为降低反演误差带来的偏差,对小绝对值元素分组重排,并微调LDM编码器以增强水印鲁棒性。实验表明,该方法生成图像质量优于现有最先进(SOTA)技术,且在各类常见攻击下均保持95%以上的水印识别准确率,显著优于已有方案。

原文摘要 · Abstract (English)

Image generation algorithms are increasingly integral to diverse aspects of human society, driven by their practical applications. However, insufficient oversight in artificial Intelligence generated content (AIGC) can facilitate the spread of malicious content and increase the risk of copyright infringement. Among the diverse range of image generation models, the Latent Diffusion Model (LDM) is currently the most widely used, dominating the majority of the Text-to-Image model market. Currently, most attribution methods for LDMs rely on directly embedding watermarks into the generated images or their intermediate noise, a practice that compromises both the quality and the robustness of the generated content. To address these limitations, we introduce TraceMark-LDM, an novel algorithm that integrates watermarking to attribute generated images while guaranteeing non-destructive performance. Unlike current methods, TraceMark-LDM leverages watermarks as guidance to rearrange random variables sampled from a Gaussian distribution. To mitigate potential deviations caused by inversion errors, the small absolute elements are grouped and rearranged. Additionally, we fine-tune the LDM encoder to enhance the robustness of the watermark. Experimental results show that images synthesized using TraceMark-LDM exhibit superior quality and attribution accuracy compared to state-of-the-art (SOTA) techniques. Notably, TraceMark-LDM demonstrates exceptional robustness against various common attack methods, consistently outperforming SOTA methods.

水印技术扩散模型版权保护AI生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。