为视觉语言模型设计水印,兼顾版权保护与图文一致性。
VLA-Mark: A cross modal watermark for large vision-language alignment model
- 通过多尺度跨模态对齐机制指导水印嵌入,无需重新训练。
- 水印检测准确率达98.8% AUC,生成文本困惑度降低7.4%。
- 抗篡改能力强,适合需高保真图文一致性的场景。
视觉语言模型亟需在不破坏多模态一致性的前提下保护知识产权的水印方案。现有文本水印方法因偏颇的标记选择和静态策略,干扰了视觉-文本对齐,使语义关键概念易受攻击。本文提出VLA-Mark,一种基于跨模态协同的水印框架,在保持语义保真度的同时嵌入可检测水印。该方法融合局部图像块相似性、全局语义连贯性和上下文注意力模式,动态引导水印注入,无需模型重训练。熵敏感机制根据生成不确定性动态调节水印强度,低不确定性阶段优先保障视觉锚定。实验表明,相比传统方法,本方案困惑度降低7.4%,BLEU提升26.6%,水印检测准确率达98.8% AUC。在同义替换、改写等攻击下仍保持96.1%的抗攻击能力,同时维持文本-视觉一致性,确立了高质量多模态水印的新标准。
原文摘要 · Abstract (English)
Vision-language models demand watermarking solutions that protect intellectual property without compromising multimodal coherence. Existing text watermarking methods disrupt visual-textual alignment through biased token selection and static strategies, leaving semantic-critical concepts vulnerable. We propose VLA-Mark, a vision-aligned framework that embeds detectable watermarks while preserving semantic fidelity through cross-modal coordination. Our approach integrates multiscale visual-textual alignment metrics, combining localized patch affinity, global semantic coherence, and contextual attention patterns, to guide watermark injection without model retraining. An entropy-sensitive mechanism dynamically balances watermark strength and semantic preservation, prioritizing visual grounding during low-uncertainty generation phases. Experiments show 7.4% lower PPL and 26.6% higher BLEU than conventional methods, with near-perfect detection (98.8% AUC). The framework demonstrates 96.1\% attack resilience against attacks such as paraphrasing and synonym substitution, while maintaining text-visual consistency, establishing new standards for quality-preserving multimodal watermarking
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。