给扩散模型生成图加水印,简单高效还防篡改
SERUM: Simple, Efficient, Robust, and Unifying Marking for Diffusion-based Image Generation
- 仅在初始噪声中加唯一水印噪声,轻量检测器识别
- 在1%误报率下真阳性率最高,抗各种图像修改
- 支持多用户个性化水印,适合实际部署
我们提出SERUM:一种针对扩散模型生成图像的简单、高效、鲁棒且统一的标记方法。仅在扩散生成的初始噪声中添加唯一水印噪声,并训练轻量级检测器识别水印图像,简化并融合了先前方法的优势。SERUM对任意图像增强或水印移除攻击均具有鲁棒性,且效率极高,对图像质量影响可忽略。相比以往方法通常仅对有限扰动有效,且训练、注入、检测成本高,SERUM在多数场景下实现了最高真阳性率(TPR)与1%假阳性率(FPR)的平衡,具备快速注入与检测能力及低检测器训练开销。其解耦架构还可无缝支持多用户,嵌入个性化水印且互不干扰。总体而言,该方法为扩散模型输出标记提供了实用方案,能可靠区分生成图像与自然图像。
原文摘要 · Abstract (English)
We propose SERUM: an intriguingly simple yet highly effective method for marking images generated by diffusion models (DMs). We only add a unique watermark noise to the initial diffusion generation noise and train a lightweight detector to identify watermarked images, simplifying and unifying the strengths of prior approaches. SERUM provides robustness against any image augmentations or watermark removal attacks and is extremely efficient, all while maintaining negligible impact on image quality. In contrast to prior approaches, which are often only resilient to limited perturbations and incur significant training, injection, and detection costs, our SERUM achieves remarkable performance, with the highest true positive rate (TPR) at a 1% false positive rate (FPR) in most scenarios, along with fast injection and detection and low detector training overhead. Its decoupled architecture also seamlessly supports multiple users by embedding individualized watermarks with little interference between the marks. Overall, our method provides a practical solution to mark outputs from DMs and to reliably distinguish generated from natural images.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。