arXiv:2608.03539cs.CV2026-08

让水印绑定图像语义,防篡改且不损画质。

IRIS: Visual-Semantic Binding for Forgery-Resistant Watermarking of Diffusion Images

论文配图:IRIS: Visual-Semantic Binding for Forgery-Resistant Watermarking of Diffusion Images
图 1 · 摘自论文原文
  • 水印基于生成图像的语义编码,嵌入时态末期。
  • 对语义变化敏感,对常见处理鲁棒,误检率低。
  • 无需训练,适合真实场景的版权保护。

大多数扩散模型生成的水印独立于图像内容,攻击者可将其移植到非生成图像上造成伪造。将水印与视觉语义绑定可防止此类移植,但现有方法依赖代理图像而非目标图像本身。实现生成过程中的真实语义绑定面临两大挑战:水印需源自图像本身,却在图像生成前进入采样轨迹,可能改变其绑定的语义;同时需在语义变化时失效,又要在常见处理下保持稳定。本文提出IRIS,一种无需训练的水印方案,通过从非水印生成图像中提取内容编码,结合秘密密钥生成一次性环形码,并在同轨迹的最后低噪声步骤中融合该码,确保绑定语义已确定。为满足相反敏感性需求,编码通过嵌入式标准化机制读取,对常见失真和轻微再生保持稳定,语义变化时则翻转。检测仅需查询图像和密钥重算环形码,因此在非本源或拼接图像上失效,接受度与语义偏移一致。在三个提示数据集上,IRIS检测可靠,保真度接近同种子无水印样本,而生成内水印无法达到此水平。相比固定模式水印易被转移、后处理水印易被再生抹除,唯有IRIS能同时抵御二者。

原文摘要 · Abstract (English)

Most in-generation diffusion watermarks embed patterns independent of the image that carries them, and attackers transplant the marks onto images the generator did not produce, resulting in forgery. Binding the mark to visual semantics prevents such transplantation, yet existing bindings anchor to a proxy image rather than the image they mark. Realizing visual-semantic binding inside generation faces two challenges. The mark derives from the image itself yet enters the sampling trajectory before that image exists, and may itself shift the semantics it binds. The binding also meets opposite sensitivity demands, breaking under semantic change while holding through common processing. We present IRIS, a training-free watermarking scheme that embeds an Intrinsic Ring Identifier from Semantics. IRIS reads a content code from the non-watermarked generated image, derives a one-time ring from the code and a secret key, returns to the final low-noise steps of the same trajectory and blends the ring in, after the semantics it binds are settled. To meet the opposite sensitivity demands, the code is read through a canonicalization shared between embedding and detection, holding through common distortions and mild regeneration while flipping under semantic change. Detection recomputes the ring from the query image and the key alone, and the mark therefore fails on a foreign or spliced image, with acceptance tracking semantic displacement. On three prompt datasets IRIS detects reliably and stays close to its same-seed non-watermarked counterpart, a fidelity prior in-generation marks do not reach. While forgeries transfer fixed-pattern marks and regeneration strips post-hoc marks, IRIS alone among the compared marks withstands both.

水印扩散模型版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。