arXiv:2603.00150cs.CVcs.CY2026-03ICCV被引 2

扩散模型可绕过水印复制受版权保护图像,威胁内容安全。

Attention to Neural Plagiarism: Diffusion Models Can Plagiarize Your Copyrighted Images!

论文配图:Attention to Neural Plagiarism: Diffusion Models Can Plagiarize Your Copyrighted Images!
图 1 · 摘自论文原文
  • 用反向隐变量作锚点,梯度搜索扰动实现隐蔽复制
  • 在MS-COCO和真实版权图上成功复现,突破可见/不可见水印
  • 无需训练,纯梯度优化,适合研究版权防护漏洞

本文揭示了新兴神经模型带来的数据剽窃风险。我们证明,现代神经模型(如扩散模型)可在即使使用先进水印技术保护的情况下,仍能复刻受版权保护的图像。为暴露版权保护漏洞并推动后续研究,我们提出一种通用的神经剽窃方法,可生成版权图像的伪造副本或制造版权模糊性。该方法基于“锚点与垫片”机制,以反向隐变量作为锚点,通过寻找逐渐偏离锚点隐变量的垫片扰动,从而规避水印或版权检测。通过对不同时间步的交叉注意力机制施加扰动,该方法能引入不同程度的语义修改,使模型绕过从可见商标、签名到不可见水印的各类保护。值得注意的是,该方法为纯梯度搜索,无需额外训练或微调。在MS-COCO及真实世界版权图像上的实验表明,扩散模型能够成功复现版权图像,凸显了应对神经剽窃的紧迫性。

原文摘要 · Abstract (English)

In this paper, we highlight a critical threat posed by emerging neural models: data plagiarism. We demonstrate how modern neural models (e.g., diffusion models) can replicate copyrighted images, even when protected by advanced watermarking techniques. To expose vulnerabilities in copyright protection and facilitate future research, we propose a general approach to neural plagiarism that can either forge replicas of copyrighted data or introduce copyright ambiguity. Our method, based on "anchors and shims", employs inverse latents as anchors and finds shim perturbations that gradually deviate the anchor latents, thereby evading watermark or copyright detection. By applying perturbations to the cross-attention mechanism at different timesteps, our approach induces varying degrees of semantic modification in copyrighted images, enabling it to bypass protections ranging from visible trademarks and signatures to invisible watermarks. Notably, our method is a purely gradient-based search that requires no additional training or fine-tuning. Experiments on MS-COCO and real-world copyrighted images show that diffusion models can replicate copyrighted images, underscoring the urgent need for countermeasures against neural plagiarism.

扩散模型版权保护数据剽窃水印绕过

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。