arXiv:2606.12977cs.CVcs.AI2026-06TPAMI

给图像生成模型加防伪指纹,还能防多人合谋抹除

Efficient, Robust, and Anti-Collusion Fingerprinting of Image Diffusion Models

论文配图:Efficient, Robust, and Anti-Collusion Fingerprinting of Image Diffusion Models
图 1 · 摘自论文原文
  • 把指纹嵌入个性化归一化模块的系数中,可从任意生成图恢复
  • 合谋攻击后生成质量大幅下降,FID显著升高,模型基本无法用
  • 无需重训练即可快速生成多个带指纹的模型副本,适合开发者部署

模型指纹技术通过在生成内容中嵌入用户专属标识,成为保护文本到图像(T2I)模型知识产权、防止非法分发的重要手段。本文揭示现有方法一个未被关注的系统性缺陷:对合谋攻击缺乏鲁棒性,即多个攻击者联合其模型可移除或隐藏指纹。为此,我们首次提出具备抗合谋能力的鲁棒指纹方法。该方法将指纹编码为嵌入T2I模型个性化归一化模块(PNM)系数中的比特串,确保任意生成图像均可可靠提取指纹。为防御合谋攻击并阻止未经授权的模型分发,引入基于无损函数不变参数变换的抗合谋机制,使合谋模型生成质量严重下降,几乎不可用。此外,可通过重新参数化PNM高效生成多个指纹化模型副本,无需重训练。还提出最坏情况优化策略以增强对抗模型级攻击的鲁棒性。实验表明,该方法在多种图像生成与编辑任务中保持高保真度与强鲁棒性,指纹提取准确率超过99.5%。相比现有方法,首次实现对合谋攻击的主动鲁棒性,显著提升合谋模型的FID值。

原文摘要 · Abstract (English)

Model fingerprinting, embedding user-specific identifiers (fingerprints) into generated outputs, has recently emerged as a popular solution to protect the intellectual property rights (IPR) of generative text-to-image (T2I) models and prevent unauthorized redistribution. In this work, we reveal a previously unexplored systematic vulnerability in existing generative model fingerprinting methods: they lack robustness against collusion attacks, where multiple attackers combine their models to remove or obscure the fingerprints. To address this issue, we take the first step towards a robust fingerprinting method for T2I models with anti-collusion capabilities. The proposed method encodes strings of bits, namely fingerprints, into the coefficients of a personalized normalization module (PNM) incorporated into T2I models, so that fingerprints can be reliably recovered from any generated image. To defend against collusion attacks and prevent unauthorized model redistribution, we introduce an anti-collusion mechanism based on lossless function-invariant parameter transformations. This mechanism significantly degrades the image generation quality of colluded models, making them effectively unusable. Moreover, our method allows developers to efficiently create multiple copies of fingerprinted T2I models by reparameterizing the PNM without the need for retraining. We also introduce a worst-case optimization strategy to improve robustness against model-level attacks. Our experiments demonstrate that the proposed method achieves high fidelity and robustness across multiple T2I image generation and editing tasks, with fingerprint extraction accuracy exceeding 99.5%. Compared with existing methods, our method demonstrates, for the first time, a notable proactive robustness to collusion attacks by significantly increasing the FID of colluded models.

模型指纹抗合谋图像生成版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。