为十亿级生成图像添加不可见水印,保障内容来源可信
SynthID-Image: Image watermarking at internet scale
- 用深度学习在生成图像中嵌入不可见水印
- 水印在常见图像处理下仍可被识别,视觉质量保持良好
- 适合需要验证图像真实性的平台和内容安全团队
我们提出SynthID-Image,一种基于深度学习的不可见图像水印系统,用于标注人工智能生成的视觉内容。本文详细阐述了该系统在互联网规模部署中的技术目标、威胁模型与实际挑战,重点满足有效性、保真度、鲁棒性和安全性要求。SynthID-Image已用于谷歌服务中超过十亿张图像及视频帧的水印标记,其对应的验证服务已向可信测试者开放。为全面评估,我们还实验性地引入外部模型变体SynthID-O,通过合作渠道提供。在基准测试中,SynthID-O相较于文献中其他事后水印方法,在视觉质量与对常见图像扰动的鲁棒性上均达到领先水平。尽管本工作聚焦于视觉媒体,但关于部署策略、约束条件与威胁建模的结论可推广至音频等其他模态。本文为大规模部署深度学习驱动的内容溯源系统提供了完整技术文档。
原文摘要 · Abstract (English)
We introduce SynthID-Image, a deep learning-based system for invisibly watermarking AI-generated imagery. This paper documents the technical desiderata, threat models, and practical challenges of deploying such a system at internet scale, addressing key requirements of effectiveness, fidelity, robustness, and security. SynthID-Image has been used to watermark over ten billion images and video frames across Google's services and its corresponding verification service is available to trusted testers. For completeness, we present an experimental evaluation of an external model variant, SynthID-O, which is available through partnerships. We benchmark SynthID-O against other post-hoc watermarking methods from the literature, demonstrating state-of-the-art performance in both visual quality and robustness to common image perturbations. While this work centers on visual media, the conclusions on deployment, constraints, and threat modeling generalize to other modalities, including audio. This paper provides a comprehensive documentation for the large-scale deployment of deep learning-based media provenance systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。