利用生成坍缩现象无侵入式验证文生图模型归属权
Fingerprinting Text-to-Image Diffusion Models via Collapsed Generation

- 通过分析特定输入下图像高度一致的坍缩生成现象,提取模型专属行为特征
- 在白盒与黑盒场景下均能准确识别源模型,误判率低且抗微调与混淆攻击
- 无需嵌入水印,仅需少量查询即可验证,适合版权争议中的证据提供
专有的文生图扩散模型正越来越多地以托管服务或可下载检查点形式分发,模型泄露、复制或未经授权微调时,其知识产权保护日益重要。本文提出一种基于‘坍缩生成’现象的非侵入式模型指纹框架,该现象指某些输入条件在多次随机种子下产生高度一致的图像。我们证明坍缩生成是模型学习过程的内在、依赖模型的特性,因此这些易坍缩条件暴露了模型特异的行为签名,可用于可靠的所有权验证,无需嵌入侵入式水印。在准备源模型条件后,框架可在两种访问模式下验证可疑模型:(1)白盒管道访问,可注入优化的连续嵌入;(2)仅黑盒API访问,通过自然语言提示查询服务接口。所有权证据通过可疑模型是否在随机采样中重现源模型的坍缩行为来衡量。在基于UNet和Transformer的扩散模型上进行的广泛实验表明,坍缩生成指纹能以低混淆度区分不同源模型。这些指纹在微调后的衍生模型以及常见的模型级或查询级混淆攻击下仍可验证,且仅需少量验证查询预算。结果确立了坍缩生成作为非侵入式扩散模型所有权验证的可靠内在证据来源。
原文摘要 · Abstract (English)
Proprietary text-to-image diffusion models are increasingly distributed as hosted services and downloadable checkpoints, making their intellectual property (IP) protection an increasingly critical concern when model leakage, copying, or unauthorized fine-tuning is disputed. In this work, we present a non-invasive model fingerprinting framework based on \emph{collapsed generation}, a phenomenon where certain input conditions produce highly consistent images across multiple stochastic seeds. We show that collapsed generation is an intrinsic, model-dependent property of the learned generation process. These collapse-prone conditions therefore expose model-specific behavioral signatures, enabling reliable ownership verification without embedding invasive watermarks. After preparing conditions on the source model, the framework verifies a suspect model under two access settings: (1) white-box pipeline access, where optimized continuous embeddings can be injected into the generation process, and (2) black-box API-only access, where natural language prompts are queried through the service interface. In both cases, ownership evidence is measured by whether the suspect model reproduces the source model's collapse behavior across stochastic samplings. Extensive experiments across UNet- and transformer-based diffusion models show that collapsed generation fingerprints can distinguish different source models with low confusion. These fingerprints remain verifiable in fine-tuned derivatives and under common and adaptive model- or query-level obfuscations, while requiring only a modest verification query budget. Together, these results establish collapsed generation as a reliable intrinsic evidence source for non-invasive diffusion model ownership verification.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。