arXiv:2603.10695cs.CVcs.AI2026-03

给视觉大模型加随机水印,防抄袭还难伪造。

RandMark: On Random Watermarking of Visual Foundation Models

  • 用小网络在输入图像特征中嵌入随机水印。
  • 非水印模型误检率低,水印模型漏检率也低。
  • 适合保护视觉大模型版权,防滥用和盗版。

视觉基础模型(VFMs)基于大规模多样化数据集训练,可微调以在多种下游计算机视觉任务中实现卓越性能与效率。由于数据收集和训练成本高昂,这些模型是宝贵资产,促使部分拥有者通过许可证分发以保护知识产权。本文提出一种所有权验证方法,利用小型编码器-解码器网络将数字水印嵌入一组保留输入图像的内部表示中。该方法基于随机水印嵌入,使功能拷贝模型中的水印统计特性可被检测。理论上和实验上均表明,该方法对非水印模型具有低误检率,对水印模型具有低漏检率。

原文摘要 · Abstract (English)

Being trained on large and diverse datasets, visual foundation models (VFMs) can be fine-tuned to achieve remarkable performance and efficiency in various downstream computer vision tasks. The high computational cost of data collection and training makes these models valuable assets, which motivates some VFM owners to distribute them alongside a license to protect their intellectual property rights. In this paper, we propose an approach to ownership verification of visual foundation models that leverages a small encoder-decoder network to embed digital watermarks into an internal representation of a hold-out set of input images. The method is based on random watermark embedding, which makes the watermark statistics detectable in functional copies of the watermarked model. Both theoretically and experimentally, we demonstrate that the proposed method yields a low probability of false detection for non-watermarked models and a low probability of false misdetection for watermarked models.

模型版权水印技术视觉模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。