无需训练的高鲁棒图像水印技术,抗旋转缩放变形
MaXsive: High-Capacity and Robust Training-Free Generative Image Watermarking in Diffusion Models
- 利用初始噪声嵌入水印,不依赖模型微调
- 采用X型模板设计,提升对旋转缩放的抗性
- 水印容量大且不易冲突,适合版权保护场景
扩散模型在图像生成中取得巨大成功,催生了大规模商用模型,带来版权保护和不当内容生成问题。训练自由的扩散模型水印提供低成本解决方案,但现有方法易受旋转、缩放、平移(RST)攻击影响。尽管部分方法采用精心设计的重复环形图案缓解此问题,却常导致水印容量下降,引发身份(ID)冲突。为此,我们提出MaXsive,一种训练自由的高容量、强鲁棒性扩散模型生成式水印技术。MaXsive充分利用初始噪声实现水印嵌入,不再依赖复杂的重复环形模式,而是引入X型模板以恢复RST失真。该设计显著增强鲁棒性,同时保持全容量,降低身份冲突风险。MaXsive在两个主流水印基准上验证了其在验证与识别场景下的有效性。
原文摘要 · Abstract (English)
The great success of the diffusion model in image synthesis led to the release of gigantic commercial models, raising the issue of copyright protection and inappropriate content generation. Training-free diffusion watermarking provides a low-cost solution for these issues. However, the prior works remain vulnerable to rotation, scaling, and translation (RST) attacks. Although some methods employ meticulously designed patterns to mitigate this issue, they often reduce watermark capacity, which can result in identity (ID) collusion. To address these problems, we propose MaXsive, a training-free diffusion model generative watermarking technique that has high capacity and robustness. MaXsive best utilizes the initial noise to watermark the diffusion model. Moreover, instead of using a meticulously repetitive ring pattern, we propose injecting the X-shape template to recover the RST distortions. This design significantly increases robustness without losing any capacity, making ID collusion less likely to happen. The effectiveness of MaXsive has been verified on two well-known watermarking benchmarks under the scenarios of verification and identification.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。