提出局部编码的生成模型,提升时间序列水印在编辑攻击下的可靠性。
A Locally Tokenized Generative Model for Robust Time-Series Watermarking

- 每个离散标记仅由短时窗生成,避免全局依赖导致的漂移。
- 在金融、能源、神经影像4个数据集上,检测准确率超90%且误报率稳定。
- 适合需要高可信溯源的时间序列生成任务,如金融建模与医疗信号处理。
水印是生成模型中溯源的核心工具,但其在多变量时间序列中的应用受限于后编辑攻击下的可靠性问题。现有检测器依赖全局耦合的重编码,导致零假设分布出现双向漂移:非水印样本的z-score可能向任一方向偏移,破坏校准阈值的有效性。我们认为这种不稳定性源于重编码机制,可靠检测需确保每个恢复单元仅依赖有限时间邻域。基于此,我们提出L-VQVAE——一种每个离散标记由短连续窗口生成的生成模型,以及基于该标记空间的LVQMark水印方法,结合对数几率偏置注入与鲁棒重编码,实现攻击时刻检测。在涵盖金融、能源与神经影像的四个基准测试中,该方法在保持生成质量的同时,显著提升了后编辑攻击下的检测能力与假阳性稳定性。
原文摘要 · Abstract (English)
Watermarking is a central tool for provenance in generative models, yet its application to multivariate time series remains hindered by reliability failures under post-editing attacks. We show that existing detectors, which rely on globally coupled re-encoding, suffer from bidirectional drift of the null distribution: post-editing attacks can shift the z-score of non-watermarked samples in either direction, invalidating clean-calibrated thresholds. We argue that this instability is a property of the re-encoding, and that reliable detection requires each recovered unit to depend only on a bounded temporal neighborhood. Guided by this principle, we propose L-VQVAE, a generative model in which each discrete token is produced from a short contiguous window, and LVQMark, a watermarking method over this token space that combines logit-bias injection with robust re-encoding for attack-time detection. Experiments on four benchmarks spanning finance, energy, and neuroimaging show that our approach preserves generation quality while stabilizing both detection power and false-positive behavior under post-editing attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。