arXiv:2601.20310cs.CRcs.CV2026-01被引 2

让水印绑定图像语义,防伪造攻击

SemBind: Binding Diffusion Watermarks to Semantics Against Black-Box Forgery Attacks

  • 用水印与图像语义关联的掩码器,使水印难以被复制
  • 在四种主流水印方法上显著降低伪造误接受率
  • 兼容现有方案,可调节安全与鲁棒性平衡

基于潜在空间的水印可简化生成图像的检测与溯源,但近期黑盒伪造攻击(需一个带水印图像及对模型的黑盒访问)可将提供方水印嵌入非其生成的图像,严重威胁真实性与可信度。我们提出SemBind,首个针对此类攻击的防御框架,通过学习语义掩码器将潜在信号绑定至图像语义,实现对黑盒伪造的抵抗。掩码器采用对比学习训练,对同一提示生成近似不变的编码,不同提示间编码近乎正交;这些编码经重塑与置换后调制目标潜在表示,在标准潜伏水印前应用。SemBind通用兼容现有潜伏水印方案,几乎不损害图像质量,且通过简单掩码比例参数实现抗伪造强度与鲁棒性的可控权衡。在四种主流潜伏水印方法上,其增强版本在黑盒伪造下显著降低误接受率,并提供可调的安全-鲁棒平衡。

原文摘要 · Abstract (English)

Latent-based watermarks, integrated into the generation process of latent diffusion models (LDMs), simplify detection and attribution of generated images. However, recent black-box forgery attacks, where an attacker needs at least one watermarked image and black-box access to the provider's model, can embed the provider's watermark into images not produced by the provider, posing outsized risk to provenance and trust. We propose SemBind, the first defense framework for latent-based watermarks that resists black-box forgery by binding latent signals to image semantics via a learned semantic masker. Trained with contrastive learning, the masker yields near-invariant codes for the same prompt and near-orthogonal codes across prompts; these codes are reshaped and permuted to modulate the target latent before any standard latent-based watermark. SemBind is generally compatible with existing latent-based watermarking schemes and keeps image quality essentially unchanged, while a simple mask-ratio parameter offers a tunable trade-off between anti-forgery strength and robustness. Across four mainstream latent-based watermark methods, our SemBind-enabled anti-forgery variants markedly reduce false acceptance under black-box forgery while providing a controllable robustness-security balance.

水印防御扩散模型语义绑定对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。