提出一种保持高斯性且抗攻击的扩散模型隐空间水印方法
Correlation-Aware and Gaussianity-Preserving Robust Latent Angular Watermarking for Diffusion Models

- 将水印编码为隐变量对间的反向角度(±π/2),利用各向同性高斯的旋转不变性
- 理论证明解码误差方差与隐变量模长成反比,且水印后相关性仅存在于特定位置
- 方法可抵御检测与移除攻击,适合需版权保护的生成模型部署
扩散模型的隐空间水印直接嵌入隐变量先验,具有不侵入参数、无缝集成生成过程的优点。然而,现有方法在隐空间反演时因违反隐变量高斯性或对正常及恶意扰动敏感,易遭水印检测或移除攻击。此外,水印后隐变量独立同分布条件被破坏,导致隐变量相关性退化和生成保真度下降,虽可通过FID外测,但其内部相关结构尚未严格刻画。为此,受各向同性高斯的旋转不变性启发,我们提出 extit{隐空间角水印(LAW)},将水印比特编码为不相交隐变量对之间的反向角度(相对于参考对为±π/2),同时保持高斯性。反向编码最大化比特值间的几何分离,理论证明解码角度误差方差与隐变量对模长成反比,即$ ext{var}(Δϕ) /propto 1/ρ^2$。进一步提出幅度驱动变体LAW-M,将水印锚定在几何最稳定的隐维度,获得额外鲁棒性提升。理论上,我们严格刻画了诱导的相关性退化,闭式推导出水印后隐变量的自相关结构,证明相关性仅限于一组稀疏、有结构的非对角元素,且取值固定为±π/4。
原文摘要 · Abstract (English)
Latent domain watermarking for diffusion models embeds watermarks directly into the latent prior, enjoying non-intrusiveness to model parameters and seamless integration with the generation process. However, due to the violation of latent Gaussianity or sensitivity to normal and malicious perturbations during latent inversion, existing methods are prone to watermark detection or removal attacks. A further overlooked problem is the violation of the i.i.d. latent condition after watermarking, which leads to latent correlation degradation and generation fidelity loss. Although this has been externally measured by FID, the internal correlation structure has yet to be rigorously characterized. To address the above issues, and motivated by the rotation-invariant property of isotropic Gaussian, we propose \textit{Latent Angular Watermarking (LAW)}, which encodes watermark bits as antipodal angles ($\pmπ/2$ relative to a reference pair) between disjoint pairs of latent elements while preserving the Gaussianity. The antipodal ($π$-separation) encoding maximizes geometric separation between bit values, and we prove that the decoding angular-error variance is proportional to the norm of the latent pair, i.e., $\operatorname{var}(Δϕ) \propto 1/ρ^2$. We further propose a magnitude-driven variant, LAW-M, which anchors watermark bits in the most geometrically stable latent dimensions, yielding additional robustness gains. Theoretically, we provide a rigorous characterization of the induced correlation degradation, deriving in closed form the autocorrelation structure of the watermarked latent and proving that correlations are confined to a sparse, structured set of off-diagonal elements with fixed $\pmπ/4$ values.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。