研究树环水印在生成模型中的检测极限,发现现有方法在去噪逆推上存在瓶颈。
Detection Limits and Statistical Separability of Tree Ring Watermarks in Rectified Flow-based Text-to-Image Generation Models
- 通过对比SD 2.1与FLUX.1-dev模型,分析文本引导与攻击对抗下的水印可检测性。
- 发现去噪逆推能力不足导致水印恢复失败,且水印图与正常图难以统计分离。
- 适用于关注生成图像溯源与水印鲁棒性的研究人员和安全评估者。
树环水印是认证AI生成图像的重要技术,但在基于修正流的模型中其有效性尚未被充分探索,尤其面临噪声潜在空间逆推的固有挑战。我们通过大量实验,评估并比较了SD 2.1与FLUX.1-dev模型中水印的检测与可分性。通过分析不同文本引导配置及增强攻击,揭示了逆推限制如何影响水印恢复,以及水印图像与未水印图像之间的统计可分性。研究结果揭示了当前顶级模型下树环水印的局限性,并强调改进逆推方法对实现可靠水印检测与区分的必要性。官方代码、数据集与所有实验结果已公开于该链接:https://github.com/dsgiitr/flux-watermarking。
原文摘要 · Abstract (English)
Tree-Ring Watermarking is a significant technique for authenticating AI-generated images. However, its effectiveness in rectified flow-based models remains unexplored, particularly given the inherent challenges of these models with noise latent inversion. Through extensive experimentation, we evaluated and compared the detection and separability of watermarks between SD 2.1 and FLUX.1-dev models. By analyzing various text guidance configurations and augmentation attacks, we demonstrate how inversion limitations affect both watermark recovery and the statistical separation between watermarked and unwatermarked images. Our findings provide valuable insights into the current limitations of Tree-Ring Watermarking in the current SOTA models and highlight the critical need for improved inversion methods to achieve reliable watermark detection and separability. The official implementation, dataset release and all experimental results are available at this \href{https://github.com/dsgiitr/flux-watermarking}{\textbf{link}}.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。