arXiv:2604.16363cs.CRcs.AI2026-04

通过组合语义探测,实现对文本生成图像模型的黑盒指纹追踪。

CSF: Black-box Fingerprinting via Compositional Semantics for Text-to-Image Models

论文配图:CSF: Black-box Fingerprinting via Compositional Semantics for Text-to-Image Models
图 1 · 摘自论文原文
  • 用组合式模糊提示探测模型输出,识别微调痕迹。
  • 在6个模型家族13个变体上实现高精度溯源,置信度达标。
  • 适合版权方在不接触模型内部的情况下追责滥用行为。

文本到图像模型是商业价值极高的资产,常以受限制许可证分发,但授权有效性依赖于违规检测。现有方法需部署前加水印或访问模型内部,难以应用于商业API场景。本文提出组合语义指纹(CSF),首个仅通过查询访问即可追溯微调模型来源的黑盒方法。CSF将模型视为语义类别生成器,用组合式模糊提示进行探测,这些提示在微调后仍保持稀有性。这为知识产权持有者带来不对称优势:可在部署后动态生成新提示,而攻击者需预判并抑制更广范围的指纹空间。在6个模型族(FLUX、Kandinsky、SD1.5/2.1/3.0/XL)及13个微调变体上,基于贝叶斯的溯源框架实现了可控风险的谱系判定,所有变体均满足主导性标准。

原文摘要 · Abstract (English)

Text-to-image models are commercially valuable assets often distributed under restrictive licenses, but such licenses are enforceable only when violations can be detected. Existing methods require pre-deployment watermarking or internal model access, which are unavailable in commercial API deployments. We present Compositional Semantic Fingerprinting (CSF), the first black-box method for attributing fine-tuned text-to-image models to protected lineages using only query access. CSF treats models as semantic category generators and probes them with compositional underspecified prompts that remain rare under fine-tuning. This gives IP owners an asymmetric advantage: new prompt compositions can be generated after deployment, while attackers must anticipate and suppress a much broader space of fingerprints. Across 6 model families (FLUX, Kandinsky, SD1.5/2.1/3.0/XL) and 13 fine-tuned variants, our Bayesian attribution framework enables controlled-risk lineage decisions, with all variants satisfying the dominance criterion.

图像生成指纹追踪黑盒检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。