arXiv:2602.09284cs.CVcs.AI2026-02被引 1

为胸部X光片设计可鲁棒验证的视觉水印,保护数据版权。

X-Mark: Saliency-Guided Robust Dataset Ownership Verification for Medical Imaging

  • 基于显著区域生成样本专属水印,保持诊断质量
  • 在CheXpert上实现100%水印识别率,误报率降12%
  • 抗缩放与自适应攻击,适合医疗影像版权保护

高质量医学影像数据集对深度学习模型训练至关重要,但未经授权使用引发严重版权与伦理问题。现有针对自然图像的版权验证方法难以适用于医学影像,因其静态水印在动态、高分辨率且视觉多样性低的扫描中表现不佳,且需保持诊断准确性。本文提出X-Mark,一种用于胸部X光片版权保护的样本特定干净标签水印方法。X-Mark利用条件U-Net在每张图像的显著区域生成独特扰动,设计多组件训练目标以保障水印有效性、对抗动态缩放过程、维持诊断质量与视觉可区分性。通过引入拉普拉斯正则化惩罚高频扰动,实现水印尺度不变性。所有权验证在黑盒环境下进行,检测可疑模型中的特征行为。在CheXpert数据集上的大量实验表明,X-Mark实现100%水印识别率(WSR),在Ind-M场景下将误报概率降低12%,并展现出对潜在自适应攻击的抵抗力。

原文摘要 · Abstract (English)

High-quality medical imaging datasets are essential for training deep learning models, but their unauthorized use raises serious copyright and ethical concerns. Medical imaging presents a unique challenge for existing dataset ownership verification methods designed for natural images, as static watermark patterns generated in fixed-scale images scale poorly dynamic and high-resolution scans with limited visual diversity and subtle anatomical structures, while preserving diagnostic quality. In this paper, we propose X-Mark, a sample-specific clean-label watermarking method for chest x-ray copyright protection. Specifically, X-Mark uses a conditional U-Net to generate unique perturbations within salient regions of each sample. We design a multi-component training objective to ensure watermark efficacy, robustness against dynamic scaling processes while preserving diagnostic quality and visual-distinguishability. We incorporate Laplacian regularization into our training objective to penalize high-frequency perturbations and achieve watermark scale-invariance. Ownership verification is performed in a black-box setting to detect characteristic behaviors in suspicious models. Extensive experiments on CheXpert verify the effectiveness of X-Mark, achieving WSR of 100% and reducing probability of false positives in Ind-M scenario by 12%, while demonstrating resistance to potential adaptive attacks.

医学影像水印技术版权保护深度学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。