通过扩散模型轨迹偏移实现抗攻击的AI图像版权保护
Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection
- 用密钥控制去噪路径,实现内容与身份的语义耦合
- 12种攻击下验证准确率达98.43%,较最优方法提升37.25%
- 无需训练,可直接嵌入扩散模型,适合内容创作者使用
随着AIGC在创作流程中普及,用户生成AI图像的版权保护成为新挑战。现有水印方法(1)易受真实世界对抗攻击,常需在防伪造和防移除之间权衡;(2)无法支持语义级篡改定位。我们提出PAI,一种无需训练的内在水印框架,可无缝集成至基于扩散模型的AIGC服务。PAI同时实现三项功能:鲁棒所有权验证、攻击检测与语义级篡改定位。不同于传统在扩散模型噪声初始化阶段嵌入水印的方法,我们设计了新型密钥条件偏移机制,根据用户密钥微妙引导去噪轨迹。这种轨迹级耦合进一步增强身份与内容的语义纠缠,显著提升对真实世界威胁的鲁棒性。此外,我们还提供理论分析证明仅有有效密钥可通过验证。在12种攻击方法上的实验表明,PAI验证准确率达98.43%,平均优于现有最佳方法37.25%,即使面对先进AIGC编辑仍保持强篡改定位能力。代码已开源:https://github.com/QingyuLiu/PAI。
原文摘要 · Abstract (English)
Protecting the copyright of user-generated AI images is an emerging challenge as AIGC becomes pervasive in creative workflows. Existing watermarking methods (1) remain vulnerable to real-world adversarial threats, often forced to trade off between defenses against spoofing and removal attacks; and (2) cannot support semantic-level tamper localization. We introduce PAI, a training-free inherent watermarking framework for AIGC copyright protection, plug-and-play with diffusion-based AIGC services. PAI simultaneously provides three key functionalities: robust ownership verification, attack detection, and semantic-level tampering localization. Unlike existing inherent watermark methods that only embed watermarks at noise initialization of diffusion models, we design a novel key-conditioned deflection mechanism that subtly steers the denoising trajectory according to the user key. Such trajectory-level coupling further strengthens the semantic entanglement of identity and content, thereby further enhancing robustness against real-world threats. Moreover, we also provide a theoretical analysis proving that only the valid key can pass verification. Experiments across 12 attack methods show that PAI achieves 98.43\% verification accuracy, improving over SOTA methods by 37.25\% on average, and retains strong tampering localization performance even against advanced AIGC edits. Our code is available at https://github.com/QingyuLiu/PAI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。