arXiv:2506.11371cs.CV2025-06被引 6

为自回归图像生成模型设计无损水印,防伪造更可信

A Watermark for Auto-Regressive Image Generation Models

  • 用聚类思想统一相似标记,解决生成时的分词错位问题
  • 在主流平台测试中,水印可检测性优于现有无损方法
  • 适合需要防伪造的图像生成应用,如版权保护与内容溯源

图像生成模型的快速发展推动了视觉内容创作的变革,能生成高度逼真且语义准确的图像。但其滥用风险(如深度伪造、图像钓鱼、误导性图像制造)凸显了真实性验证机制的必要性。尽管传统统计水印在自回归语言模型中有效,但直接用于图像生成模型时面临‘重分词不匹配’难题——生成过程中原始序列与重分词序列存在差异。为此,我们提出C-reweight,一种专为图像生成模型设计的无损水印方法。该方法采用基于聚类的策略,将同一簇内的标记视为等价,从而缓解重分词不匹配问题,同时保持图像质量。在主流图像生成平台上的广泛评估表明,C-reweight不仅维持了生成图像的视觉保真度,还显著提升了水印可检测性,超越现有无损水印技术,树立了安全可信图像合成的新标准。

原文摘要 · Abstract (English)

The rapid evolution of image generation models has revolutionized visual content creation, enabling the synthesis of highly realistic and contextually accurate images for diverse applications. However, the potential for misuse, such as deepfake generation, image based phishing attacks, and fabrication of misleading visual evidence, underscores the need for robust authenticity verification mechanisms. While traditional statistical watermarking techniques have proven effective for autoregressive language models, their direct adaptation to image generation models encounters significant challenges due to a phenomenon we term retokenization mismatch, a disparity between original and retokenized sequences during the image generation process. To overcome this limitation, we propose C-reweight, a novel, distortion-free watermarking method explicitly designed for image generation models. By leveraging a clustering-based strategy that treats tokens within the same cluster equivalently, C-reweight mitigates retokenization mismatch while preserving image fidelity. Extensive evaluations on leading image generation platforms reveal that C-reweight not only maintains the visual quality of generated images but also improves detectability over existing distortion-free watermarking techniques, setting a new standard for secure and trustworthy image synthesis.

图像生成水印技术防伪造

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。