用压缩感知设计防伪造水印,确保只有持有密钥者才能验证图像归属。
CSGuard: Toward Forgery-Resistant Watermarking in Diffusion Models via Compressed Sensing Constraint

- 引入压缩感知约束,将水印生成与验证绑定到秘密矩阵。
- 攻击成功率从100%降至28.12%,正常水印检测率达100%。
- 无需训练,保护生成质量,适合版权保护与数字取证场景。
基于潜在空间的扩散模型水印将水印嵌入生成图像的潜在表示中,实现内容溯源,提供无需训练的知识产权保护与数字取证方案。然而,此类方法对伪造攻击存在严重漏洞:攻击者可通过逆向重构水印图像并使用任意提示词重生成,从而在恶意内容上实现虚假归属。本文提出 CSGuard,首个具备防伪造能力的水印方案,利用压缩感知将水印生成与验证绑定至秘密矩阵。只有持有该矩阵的用户才能正确嵌入或验证水印,有效防止非法用户伪造,同时不损害生成质量与水印完整性。实验表明,CSGuard 实现强防伪造能力,将攻击成功率从100.0%降至28.12%,对正常水印图像实现100%检测率,且不影响水印有效性。
原文摘要 · Abstract (English)
Latent-based diffusion model watermarking embeds watermarks into generated images' latent space to enable content attribution, offering a training-free solution for intellectual property protection and digital forensics. However, these methods exhibit a critical vulnerability to the forgery attack, attackers can extract the watermark by inverting the watermarked image and re-generating it with an arbitrary prompt, thereby enabling false attribution on malicious content. In this paper, we propose the CSGuard, the first forgery-resistant watermarking schema that leverages compressed sensing to bind the watermarked image generation and verification to a secret matrix. This ensures that only users possessing the secret matrix can correctly embed or verify the image watermark, prevents the illegal users from forgery without compromising generation quality and watermark integrity. Experimental results demonstrate that CSGuard achieves strong forgery resistance, reduces the attack success rate from 100.0\% to 28.12\%, and achieve 100\% detection rate on benign watermarked images without compromising watermarking effectiveness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。