arXiv:2606.28092cs.CV2026-06

通过频谱特性识别扩散模型来源,准确率达99.9%

Diffusion Model Attribution via Spectral Coupling of Denoiser Responses

论文配图:Diffusion Model Attribution via Spectral Coupling of Denoiser Responses
图 1 · 摘自论文原文
  • 利用频率扰动探测去噪过程中的频谱能量分布特征
  • 在8个不同模型上达到99.9%的识别准确率,跨领域提示下仍达96.2%
  • 无需生成或优化,适用于无侵入式模型溯源

将生成图像归因于其源扩散模型是出处验证与知识产权保护中的基础挑战。由于在不同数据集上训练的扩散模型可能收敛至相似的得分函数和输出分布,导致生成图像本身难以作为可靠证据。现有非侵入式方法在架构相似的变体上表现不佳,或依赖于在共享自编码器时消失的信号。我们提出频谱去噪签名(Spectral Denoising Signatures, SDS),一种通过指纹化候选模型的去噪行为实现非侵入式归因的方法。核心洞察在于,模型的去噪得分函数具有独特的频谱几何特性,体现在去噪过程中能量在空间频带间的重分布。通过频率控制的扰动探测该行为,SDS提取出仅依赖模型本身的稳定签名,仅需标准前向传播,无需反演、优化或生成时注册。实验表明,SDS在八个多样化扩散模型上实现约99.9%准确率,在跨领域提示偏移下仍保持96.2%准确率,优于各类非侵入基线,覆盖训练数据、架构和训练流程差异,确立频谱几何作为扩散模型归因的理论与实践基础。代码已公开于:https://github.com/Pragati-Meshram/SGS

原文摘要 · Abstract (English)

Attributing a generated image to its source diffusion model is a fundamental challenge in provenance verification and intellectual property protection. This problem is particularly difficult because diffusion models trained on different datasets can converge to similar score functions and thus similar output distributions, making the generated images themselves unreliable as attribution evidence. Existing non-invasive methods either fail on architecturally similar variants or rely on signals that vanish when models share the same autoencoder. We propose Spectral Denoising Signatures (SDS), a non-invasive attribution method that identifies the source model by fingerprinting each candidate model's denoising behavior. Our key insight is that a model's denoising score function exhibits a distinctive spectral geometry, reflected in how it redistributes energy across spatial frequency bands during denoising. By probing this behavior with frequency-controlled perturbations, SDS extracts a stable signature that is intrinsic to the model, requiring only standard forward passes with no inversion, optimization, or generation-time enrollment. Our results demonstrate that SDS achieves approximately 99.9% accuracy across eight diverse diffusion models and 96.2% under cross-domain prompt shift, outperforming non-invasive baselines across variations in training data, architecture, and training procedure, establishing spectral geometry as a principled and practical basis for diffusion model attribution. Code is available at: https://github.com/Pragati-Meshram/SGS

模型溯源扩散模型频谱分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。