在冻结的扩散模型中实现高效多比特水印,支持跨模型追踪。
Transferable Multi-Bit Watermarking Across Frozen Diffusion Models via Latent Consistency Bridges
- 通过潜在一致性模型构建可微桥梁,在每步去噪中嵌入持久扰动。
- 单次前向传播16.4毫秒内完成64位水印提取,速度提升45倍。
- 无需重训练,支持跨架构传递,适合政策监管与内容溯源场景。
随着生成式AI的发展,全球治理框架日益要求内容出处可验证。然而,现有水印技术存在政策与技术脱节问题:基于采样的方法需计算量巨大的反演,微调方法则依赖特定模型检查点,难以实现标准化跨模型监管。为此,我们提出DiffMark,一种即插即用的多比特水印框架。DiffMark将可学习的持久扰动嵌入冻结扩散模型的每一步去噪过程,在最终潜空间累积可恢复信号。为实现通过冻结网络的高效训练,我们采用潜在一致性模型(LCMs)作为可微训练桥接。DiffMark在单次16.4毫秒前向传播中完成64位提取,较反演基线提速45倍。通过支持逐图像密钥灵活性和跨架构可迁移性而无需重训练,DiffMark提供了实现用户问责与落实新兴AI治理要求所需的实用、可扩展技术工具。
原文摘要 · Abstract (English)
As generative AI advances, global governance frameworks increasingly mandate verifiable content provenance. However, existing watermarking techniques face a critical policy-to-technology disconnect: sampling-based methods require computationally prohibitive inversion, while fine-tuning approaches are tethered to specific model checkpoints, hindering standardized, cross-model oversight. To bridge this gap, we introduce DiffMark, a plug-and-play multi-bit watermarking framework. DiffMark embeds a persistent, learned perturbation into every denoising step of a frozen diffusion model, accumulating a recoverable signal in the final latent space. To enable efficient training through the frozen network, we utilize Latent Consistency Models (LCMs) as a differentiable training bridge. DiffMark achieves 64-bit extraction in a single 16.4 ms forward pass, which is a $45\times$ speed-up over inversion baselines. By enabling per-image key flexibility and cross-architecture transferability without retraining, DiffMark provides the practical, scalable technical tooling necessary to operationalize user accountability and enforce emerging AI governance mandates.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。