首个保护多模态RAG图像版权的水印框架
Safeguarding Multimodal Knowledge Copyright in the RAG-as-a-Service Environment
- 用缩写触发和空间关系在合成图中嵌入语义水印
- 水印可抵御图像检索到文本生成的传播干扰,保持隐蔽性
- 适用于共享知识库的多模态AI服务版权保护
随着检索增强生成(RAG)向服务化平台(Rag-as-a-Service)演进,共享知识库中的数据版权保护变得至关重要。现有RAG水印方法仅针对文本知识,未能覆盖图像内容。本文提出AQUA,首个面向多模态RAG系统中图像知识的水印框架。AQUA通过缩写触发和空间关系线索两种互补方式,在合成图像中嵌入语义信号,确保水印在从图像检索器到文本生成器的间接传播中仍能保留,具备高效、隐蔽且可靠的特点。跨多种模型与数据集的实验表明,AQUA实现了稳健、隐形且可信的版权溯源,填补了多模态RAG版权保护的关键空白。
原文摘要 · Abstract (English)
As Retrieval-Augmented Generation (RAG) evolves into service-oriented platforms (Rag-as-a-Service) with shared knowledge bases, protecting the copyright of contributed data becomes essential. Existing watermarking methods in RAG focus solely on textual knowledge, leaving image knowledge unprotected. In this work, we propose AQUA, the first watermark framework for image knowledge protection in Multimodal RAG systems. AQUA embeds semantic signals into synthetic images using two complementary methods: acronym-based triggers and spatial relationship cues. These techniques ensure watermark signals survive indirect watermark propagation from image retriever to textual generator, being efficient, effective and imperceptible. Experiments across diverse models and datasets show that AQUA enables robust, stealthy, and reliable copyright tracing, filling a key gap in multimodal RAG protection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。