arXiv:2601.21252cs.CRcs.CV2026-01被引 1

无需修改模型即可无损验证扩散模型版权。

Lossless Copyright Protection via Intrinsic Model Fingerprinting

  • 通过确定性生成路径提取模型唯一指纹。
  • 黑盒接口下仍能准确验证版权,抗模型修改能力强。
  • 适合保护高价值扩散模型知识产权的场景。

扩散模型性能卓越,成为高价值知识产权,但也面临未经授权复制的风险。现有保护方法要么修改模型嵌入水印(损害性能),要么通过操控去噪过程提取指纹(不兼容黑盒API)。本文提出TrajPrint,一种完全无损且无需训练的框架,通过追踪确定性生成路径提取模型内在流形指纹进行版权验证。首先以带水印图像为锚点,精确追溯其生成轨迹起点,锁定该路径映射的模型指纹;随后采用双端锚定联合优化策略,合成符合目标流形的特定指纹噪声,确保受保护模型可恢复水印图像,非目标模型则失败。最终通过原子推理与统计假设检验实现验证。大量实验表明,TrajPrint在黑盒API场景下实现无损验证,对模型修改具有优异鲁棒性。

原文摘要 · Abstract (English)

The exceptional performance of diffusion models establishes them as high-value intellectual property but exposes them to unauthorized replication. Existing protection methods either modify the model to embed watermarks, which impairs performance, or extract model fingerprints by manipulating the denoising process, rendering them incompatible with black-box APIs. In this paper, we propose TrajPrint, a completely lossless and training-free framework that verifies model copyright by extracting unique manifold fingerprints formed during deterministic generation. Specifically, we first utilize a watermarked image as an anchor and exactly trace the path back to its trajectory origin, effectively locking the model fingerprint mapped by this path. Subsequently, we implement a joint optimization strategy that employs dual-end anchoring to synthesize a specific fingerprint noise, which strictly adheres to the target manifold for robust watermark recovery. As input, it enables the protected target model to recover the watermarked image, while failing on non-target models. Finally, we achieved verification via atomic inference and statistical hypothesis testing. Extensive experiments demonstrate that TrajPrint achieves lossless verification in black-box API scenarios with superior robustness against model modifications.

版权保护扩散模型指纹识别黑盒验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。