arXiv:2605.29809cs.CRcs.CV2026-05中稿 · ICML被引 1

为文生图模型设计可认证的版权验证方法,防篡改且抗攻击。

Cert-LAS: Toward Certified Model Ownership Verification for Text-to-Image Diffusion Models via Layer-Adaptive Smoothing

论文配图:Cert-LAS: Toward Certified Model Ownership Verification for Text-to-Image Diffusion Models via Layer-Adaptive Smoothing
图 1 · 摘自论文原文
  • 通过分层自适应噪声嵌入水印,提升鲁棒性。
  • 在恶意移除攻击下仍能可靠验证所有权,理论保证可信。
  • 适合需要防伪和版权保护的生成式AI应用开发者。

大规模文本到图像(T2I)扩散模型推动了前所未有的创作应用,但其未经授权使用引发了严重的知识产权问题,使得模型所有权验证(MOV)日益关键。我们发现,现有基于后门的扩散水印方法通常隐含假设验证过程是‘忠实’的,即验证者可查询可疑模型并获得真实的水印响应完成验证。然而,实际中对手可能故意或无意破坏潜在的水印信号,显著降低验证可靠性。为此,我们提出Cert-LAS,首个基于分层自适应平滑的可认证T2I模型所有权验证方法。Cert-LAS利用扩散分类器和LFS引导的分层自适应噪声嵌入指定水印,并通过假设检验判断可疑模型是否显著比未加水印参考模型表现出更强的水印响应来验证所有权。我们进一步证明,在特定条件下,Cert-LAS即使在恶意移除攻击下仍能实现可靠验证。大量实验验证了Cert-LAS的有效性及其对自适应攻击的抵抗能力。代码已公开于https://github.com/Leyi-Qi/Cert-LAS。

原文摘要 · Abstract (English)

Large-scale text-to-image (T2I) diffusion models have enabled unprecedented creative applications, but their unauthorized use has raised serious intellectual property concerns, making model ownership verification (MOV) increasingly critical. We find that existing backdoor-based diffusion watermarking methods often (implicitly) assume a "faithful" verification process, namely, that the verifier can query a suspicious model and obtain the faithful watermark response to complete MOV. However, in practice, adversaries may intentionally or unintentionally damage potential watermark signals, significantly degrading verification reliability. To address this issue, we propose Cert-LAS, the first certified MOV method for T2I models based on layer-adaptive smoothing. In general, Cert-LAS embeds specified watermarks using diffusion classifiers and an LFS-guided layer-adaptive noise, and verifies ownership by examining whether the suspected model exhibits significantly stronger watermark responses compared to unwatermarked references through hypothesis testing. We further prove that, under certain conditions, our Cert-LAS can still achieve reliable verification even in the presence of malicious removal attacks. Extensive experiments validate the effectiveness of Cert-LAS and its resistance to adaptive attacks. Our code is available at https://github.com/Leyi-Qi/Cert-LAS.

模型版权扩散模型水印技术可认证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。