arXiv:2603.17531cs.CVcs.AI2026-03中稿 · CVPR被引 1

利用图像块间关系不变性,实现无损且抗AI编辑的数字水印。

Rel-Zero: Harnessing Patch-Pair Invariance for Robust Zero-Watermarking Against AI Editing

  • 基于图像块对间的相对距离在编辑中保持稳定这一发现
  • 在多种编辑模型下显著优于已有零水印方法的鲁棒性
  • 适合需要无损内容认证的版权保护场景

基于扩散模型的图像编辑技术对数字视觉内容的真实性构成重大威胁。传统嵌入式水印方法常因引入可见扰动以保证鲁棒性,导致视觉质量下降。现有零水印方法多依赖全局图像特征,难以抵御复杂篡改。本文发现:尽管单个图像块在AI编辑中变化剧烈,但块对间的相对距离保持相对不变。据此提出关系型零水印(Rel-Zero),无需修改原图,仅通过提取编辑不变的块对关系生成唯一水印。该方法基于内在结构一致性而非绝对外观,实现非侵入式且强鲁棒的内容认证。大量实验表明,相比先前零水印方法,Rel-Zero在多种编辑模型与操作下展现出显著提升的鲁棒性。

原文摘要 · Abstract (English)

Recent advancements in diffusion-based image editing pose a significant threat to the authenticity of digital visual content. Traditional embedding-based watermarking methods often introduce perceptible perturbations to maintain robustness, inevitably compromising visual fidelity. Meanwhile, existing zero-watermarking approaches, typically relying on global image features, struggle to withstand sophisticated manipulations. In this work, we uncover a key observation: while individual image patches undergo substantial alterations during AI-based editing, the relational distance between patch pairs remains relatively invariant. Leveraging this property, we propose Relational Zero-Watermarking (Rel-Zero), a novel framework that requires no modification to the original image but derives a unique zero-watermark from these editing-invariant patch relations. By grounding the watermark in intrinsic structural consistency rather than absolute appearance, Rel-Zero provides a non-invasive yet resilient mechanism for content authentication. Extensive experiments demonstrate that Rel-Zero achieves substantially improved robustness across diverse editing models and manipulations compared to prior zero-watermarking approaches.

零水印内容认证扩散模型图像安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。