arXiv:2504.15026cs.CVcs.CR2025-04被引 11

提出可真实部署的无损图像水印技术,解决密钥管理与第三方验证难题。

Gaussian Shading++: Rethinking the Realistic Deployment Challenge of Performance-Lossless Image Watermark for Diffusion Models

  • 双通道设计结合纠错码,实现固定密钥下的无损水印嵌入。
  • 建模生成与逆过程为高斯噪声信道,支持参数变化下的强鲁棒性。
  • 引入公钥签名,支持第三方验证,抵抗伪造攻击,适合实际应用。

扩散模型在版权保护与不当内容生成方面的伦理问题,制约了其实际应用。水印技术是有效解决方案之一,现有方法多关注水印不降低模型性能,却忽视了真实部署中的关键挑战:密钥管理复杂、用户自定义生成参数多样、第三方难以验证等问题。为此,我们提出Gaussian Shading++,一种面向真实部署的扩散模型图像水印方法。通过双通道设计,利用伪随机纠错码编码水印伪随机化所需的随机种子,在固定水印密钥下实现无性能损失。同时,将生成与反演过程引入的失真建模为加性白高斯噪声信道,并采用新颖的软判决解码策略进行提取,确保生成参数变化时仍具备强鲁棒性。为支持第三方验证,引入公钥签名机制,即使模型逆向能力完全公开,也能提供一定抗伪造能力。大量实验表明,Gaussian Shading++不仅保持性能无损,且在鲁棒性上优于现有方法,更具实际部署价值。

原文摘要 · Abstract (English)

Ethical concerns surrounding copyright protection and inappropriate content generation pose challenges for the practical implementation of diffusion models. One effective solution involves watermarking the generated images. Existing methods primarily focus on ensuring that watermark embedding does not degrade the model performance. However, they often overlook critical challenges in real-world deployment scenarios, such as the complexity of watermark key management, user-defined generation parameters, and the difficulty of verification by arbitrary third parties. To address this issue, we propose Gaussian Shading++, a diffusion model watermarking method tailored for real-world deployment. We propose a double-channel design that leverages pseudorandom error-correcting codes to encode the random seed required for watermark pseudorandomization, achieving performance-lossless watermarking under a fixed watermark key and overcoming key management challenges. Additionally, we model the distortions introduced during generation and inversion as an additive white Gaussian noise channel and employ a novel soft decision decoding strategy during extraction, ensuring strong robustness even when generation parameters vary. To enable third-party verification, we incorporate public key signatures, which provide a certain level of resistance against forgery attacks even when model inversion capabilities are fully disclosed. Extensive experiments demonstrate that Gaussian Shading++ not only maintains performance losslessness but also outperforms existing methods in terms of robustness, making it a more practical solution for real-world deployment.

水印扩散模型鲁棒性部署

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。