通过信息瓶颈机制,让水印只保留关键信号,抵御AI重生成攻击。
WaterVIB: Learning Minimal Sufficient Watermark Representations via Variational Information Bottleneck
- 用变分信息瓶颈构建信息筛子,只保留消息的最小充分统计量。
- 在扩散模型编辑下零样本鲁棒性显著优于现有方法。
- 适合关注版权保护与对抗生成净化的AI安全研究者。
鲁棒水印对知识产权保护至关重要,但现有方法易受基于再生的AIGC攻击。我们发现其失败原因是水印与高频载体纹理纠缠,而后者在生成净化过程中易被重写。为此,提出WaterVIB框架,将编码器重构为变分信息瓶颈下的信息筛。该方法不依赖脆弱的载体细节,强制模型学习消息的最小充分统计量,有效过滤易受生成扰动的冗余载体特征,仅保留对再生不变的关键信号。理论上证明优化此瓶颈是抵御分布偏移攻击的必要条件。大量实验表明,WaterVIB显著优于现有最先进方法,在未知扩散模型编辑下实现优越的零样本鲁棒性。
原文摘要 · Abstract (English)
Robust watermarking is critical for intellectual property protection, whereas existing methods face a severe vulnerability against regeneration-based AIGC attacks. We identify that existing methods fail because they entangle the watermark with high-frequency cover texture, which is susceptible to being rewritten during generative purification. To address this, we propose WaterVIB, a theoretically grounded framework that reformulates the encoder as an information sieve via the Variational Information Bottleneck. Instead of overfitting to fragile cover details, our approach forces the model to learn a Minimal Sufficient Statistic of the message. This effectively filters out redundant cover nuances prone to generative shifts, retaining only the essential signal invariant to regeneration. We theoretically prove that optimizing this bottleneck is a necessary condition for robustness against distribution-shifting attacks. Extensive experiments demonstrate that WaterVIB significantly outperforms state-of-the-art methods, achieving superior zero-shot resilience against unknown diffusion-based editing.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。