用难移除的可见水印增强版权保护,对抗AI滥用。
Beyond Invisibility: Learning Robust Visible Watermarks for Stronger Copyright Protection
- 设计可见水印,通过概率逆问题优化增强鲁棒性。
- 在多种场景下均优于现有方法,实现长期防护。
- 适合需要持久版权保护的创作者和平台使用。
随着AI技术发展,受版权保护内容面临未经授权使用的风险,无论是模型训练还是直接滥用。现有基于不可见对抗扰动的方法仅能防御特定AI技术(如通过DreamBooth进行的非法个性化),但一旦模型架构改变便需重新训练,缺乏长期安全性。为实现更强的长期保护,本文突破不可见扰动局限,提出一种通用方案,在图像中嵌入难以移除的可见水印。基于新的概率与逆问题建模框架,该方法最大化最优重构结果与原始内容之间的差异。针对难以求解的双层优化问题,开发了高效近似算法。实验表明,该方法在多种场景下均表现出显著优势。
原文摘要 · Abstract (English)
As AI advances, copyrighted content faces growing risk of unauthorized use, whether through model training or direct misuse. Building upon invisible adversarial perturbation, recent works developed copyright protections against specific AI techniques such as unauthorized personalization through DreamBooth that are misused. However, these methods offer only short-term security, as they require retraining whenever the underlying model architectures change. To establish long-term protection aiming at better robustness, we go beyond invisible perturbation, and propose a universal approach that embeds \textit{visible} watermarks that are \textit{hard-to-remove} into images. Grounded in a new probabilistic and inverse problem-based formulation, our framework maximizes the discrepancy between the \textit{optimal} reconstruction and the original content. We develop an effective and efficient approximation algorithm to circumvent a intractable bi-level optimization. Experimental results demonstrate superiority of our approach across diverse scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。