arXiv:2508.21727cs.CRcs.AI2025-08AAAI被引 2

通过推理时优化实现鲁棒多比特图像水印。

OptMark: Robust Multi-bit Diffusion Watermarking via Inference Time Optimization

  • 分阶段嵌入结构与细节水印,提升抗攻击能力。
  • 在多种图像变换和生成攻击下保持水印可识别。
  • 适用于版权保护与用户追踪场景。

为保护扩散生成图像的版权并实现用户追踪,水印技术至关重要。然而,现有方法存在明显局限:零比特水印系统难以支持大规模用户追踪,而多比特方法对某些图像变换或生成攻击敏感,缺乏全面鲁棒性。本文提出 OptMark,一种基于优化的方法,将鲁棒多比特水印嵌入扩散去噪过程的中间潜在表示中。OptMark 在早期插入结构化水印以抵抗生成攻击,后期嵌入细节水印以应对图像变换,并采用定制正则化项保证图像质量与不可感知性。针对优化过程中内存随去噪步数线性增长的问题,OptMark 引入伴随梯度法,将内存消耗从 O(N) 降至 O(1)。实验表明,OptMark 实现了不可见的多比特水印,在值域变换、几何变换、编辑及再生攻击下均表现出强鲁棒性。

原文摘要 · Abstract (English)

Watermarking diffusion-generated images is crucial for copyright protection and user tracking. However, current diffusion watermarking methods face significant limitations: zero-bit watermarking systems lack the capacity for large-scale user tracking, while multi-bit methods are highly sensitive to certain image transformations or generative attacks, resulting in a lack of comprehensive robustness. In this paper, we propose OptMark, an optimization-based approach that embeds a robust multi-bit watermark into the intermediate latents of the diffusion denoising process. OptMark strategically inserts a structural watermark early to resist generative attacks and a detail watermark late to withstand image transformations, with tailored regularization terms to preserve image quality and ensure imperceptibility. To address the challenge of memory consumption growing linearly with the number of denoising steps during optimization, OptMark incorporates adjoint gradient methods, reducing memory usage from O(N) to O(1). Experimental results demonstrate that OptMark achieves invisible multi-bit watermarking while ensuring robust resilience against valuemetric transformations, geometric transformations, editing, and regeneration attacks.

图像水印扩散模型鲁棒性版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。