arXiv:2509.22126cs.CRcs.CV2025-09被引 4

用梯度引导实现扩散模型水印,无需重训且抗攻击能力强。

Guidance Watermarking for Diffusion Models

  • 通过外部水印解码器的梯度指导生成过程,实现嵌入式水印。
  • 不改变生成图像质量与多样性,对多种攻击保持鲁棒性。
  • 兼容现有水印方法,适合需要版权保护的生成模型应用。

本文提出一种针对扩散模型的新水印方法,基于任意现成水印解码器计算的梯度来引导扩散过程。该梯度计算包含多种图像增强操作,提升了对未预设攻击类型的鲁棒性,且无需重新训练或微调。本方法可将任意后处理水印方案转化为扩散过程中的生成嵌入。我们验证了该方法在多个扩散模型和检测器上的有效性。水印引导不会显著改变给定种子和提示下的生成图像,同时保持生成多样性和质量。

原文摘要 · Abstract (English)

This paper introduces a novel watermarking method for diffusion models. It is based on guiding the diffusion process using the gradient computed from any off-the-shelf watermark decoder. The gradient computation encompasses different image augmentations, increasing robustness to attacks against which the decoder was not originally robust, without retraining or fine-tuning. Our method effectively convert any \textit{post-hoc} watermarking scheme into an in-generation embedding along the diffusion process. We show that this approach is complementary to watermarking techniques modifying the variational autoencoder at the end of the diffusion process. We validate the methods on different diffusion models and detectors. The watermarking guidance does not significantly alter the generated image for a given seed and prompt, preserving both the diversity and quality of generation.

水印扩散模型生成安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。