arXiv:2605.16239cs.LG2026-05

将水印嵌入流匹配模型的连续动态中,实现隐蔽且不影响生成质量的版权保护。

Dynamics-Level Watermarking of Flow Matching Models with Random Codes

论文配图:Dynamics-Level Watermarking of Flow Matching Models with Random Codes
图 1 · 摘自论文原文
  • 在流匹配模型的连续速度场中添加密钥依赖扰动作为水印
  • 在MNIST和CIFAR-10上实现可靠消息恢复,生成质量无损
  • 无需密钥时解码准确率接近随机水平,适合版权追踪场景

我们提出一种面向生成模型的动力学级水印方法。不同于传统在模型权重或输出中嵌入信号的方式,本方法直接将水印嵌入流匹配模型所学习的连续动力学——即速度场中。该方法被建模为在连续信道上的随机编码:训练时加入密钥依赖的扰动,检测时通过黑盒查询恢复信息。扰动设计确保生成分布不变。在不同架构下的MNIST与CIFAR-10实验表明,消息可稳定恢复,生成质量保持完好,且无密钥时解码准确率接近随机水平。

原文摘要 · Abstract (English)

We introduce a dynamics-level approach to watermarking generative models. Rather than embedding signals into model weights or outputs, we embed the watermark directly into the learned continuous dynamics -- the velocity field of a flow matching model. We formulate this as random coding over a continuous channel: a key-dependent perturbation is added during training, and the message is recovered at detection time from black-box queries. The perturbation is designed to leave the generated distribution unchanged. Experiments on MNIST and CIFAR-10 across different architectures confirm reliable message recovery, preserved generation quality, and chance-level decoding accuracy without the secret key.

水印流匹配版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。