用零知识证明在图像生成中嵌入不可见水印,保护版权且不泄露模型信息。
ZK-WAGON: Imperceptible Watermark for Image Generation Models using ZK-SNARKs
- 利用零知识证明技术将水印嵌入图像生成过程,无需暴露模型参数。
- 通过选择性层电路构建,证明生成时间大幅缩短。
- 适合需要版权保护的AI图像生成应用,如内容创作与防伪。
随着图像生成模型日益强大且普及,合成媒体的真实性、所有权及滥用问题愈发突出。能够生成与真实图像难以区分的图像带来了虚假信息、深度伪造和知识产权侵权等风险。传统水印方法或降低图像质量,或易被移除,或需访问机密模型内部信息,难以实现安全可扩展部署。我们首次提出ZK-WAGON,一种基于零知识简洁非交互式知识论证(ZK-SNARKs)的图像生成模型水印系统。该方法可在不暴露模型权重、生成提示或任何敏感内部信息的前提下,提供可验证的来源证明。我们提出选择性层ZK电路构建(SL-ZKCC)方法,仅将模型关键层转换为电路,显著降低证明生成时间。生成的ZK-SNARK证明通过最低有效位(LSB)隐写术不可察觉地嵌入生成图像中。我们在GAN和扩散模型上验证了该系统,提供了一种安全、模型无关的可信AI图像生成方案。
原文摘要 · Abstract (English)
As image generation models grow increasingly powerful and accessible, concerns around authenticity, ownership, and misuse of synthetic media have become critical. The ability to generate lifelike images indistinguishable from real ones introduces risks such as misinformation, deepfakes, and intellectual property violations. Traditional watermarking methods either degrade image quality, are easily removed, or require access to confidential model internals - making them unsuitable for secure and scalable deployment. We are the first to introduce ZK-WAGON, a novel system for watermarking image generation models using the Zero-Knowledge Succinct Non Interactive Argument of Knowledge (ZK-SNARKs). Our approach enables verifiable proof of origin without exposing model weights, generation prompts, or any sensitive internal information. We propose Selective Layer ZK-Circuit Creation (SL-ZKCC), a method to selectively convert key layers of an image generation model into a circuit, reducing proof generation time significantly. Generated ZK-SNARK proofs are imperceptibly embedded into a generated image via Least Significant Bit (LSB) steganography. We demonstrate this system on both GAN and Diffusion models, providing a secure, model-agnostic pipeline for trustworthy AI image generation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。