arXiv:2608.28929cs.CRcs.CV2026-08中稿 · the IEEE Internati…

为扩散模型设计可验证产权的鲁棒框架,防止盗用且不影响使用效果。

Membership is Ownership: A Robust Ownership Verification Framework for Diffusion Models

论文配图:Membership is Ownership: A Robust Ownership Verification Framework for Diffusion Models
图 1 · 摘自论文原文
  • 基于私有成员数据集的群体假设检验,实现产权验证
  • 在多种攻击下仍保持稳定,误报率低于10^-6
  • 无需修改模型或采样流程,适合商业场景部署

大规模扩散模型为人工智能企业带来了诸多盈利性下游应用,如视觉编辑与内容生成。由于训练过程消耗大量资源(如计算力和高质量数据),这类模型被视为科技公司(如 OpenAI、Google)的重要知识产权资产。然而,这些模型易遭恶意用户盗用,用于定制化商业用途。现有方法多依赖训练时注入人工痕迹的水印技术,但会带来可衡量的性能损失,且易被后期微调削弱。为此,本文提出一种面向真实商业场景的扩散模型产权保护框架「会员即所有权(MiO)」,基于私有成员证据数据集的群体水平假设检验,通过成员推断与模型分离双重标准进行产权验证,显著性水平均低于10^-6。实验在DDIM与Stable Diffusion模型上进行,未修改原始模型或采样流程,报告了固定假阳性率下的ROC-AUC与真阳性率。结果表明,该方法在不同后盗用微调与权重扰动下仍具稳定性,优于传统水印方法。

原文摘要 · Abstract (English)

Large-scale diffusion models have fueled numerous profitable downstream applications for AI-related businesses, including visual editing and content creation. Meanwhile, due to the huge amount of resource consumption (e.g., computation and high-quality data) during training, such diffusion models are deemed valuable intellectual property (IP) for tech companies like OpenAI and Google. Yet, the IP assets are vulnerable to various unauthorized uses by adversaries seeking to steal models for customized, usually commercial applications. Some existing approaches have explored IP protection for AI models; however, they mostly face structural limitations in common --- using a training-time watermarking by injecting artifacts in the model, which can impose a measurable utility cost and can be weakened by post-hoc fine-tuning. To address these challenges, this work investigates IP protection (i.e., model ownership verification) for diffusion models in a realistic commercial scenario with minimal model utility loss. Specifically, the proposed method builds a framework for model ownership verification, termed ``{Membership is Ownership} (MiO)'', based on a population-level hypothesis test on a private member evidence dataset. MiO verifies ownership using two criteria: model attribution through membership inference and model separation from public references. Both are tested at $p<10^{-6}$. We evaluate MiO on DDIM and Stable Diffusion models without modifying the owner model or its sampling pipeline, and report ROC-AUC and true-positive rates at fixed nominal false-positive targets. Furthermore, MiO stays stable under different post-theft fine-tuning and weight perturbation in adversarial scenarios, reflecting better robustness compared to the watermarking methods.

模型版权扩散模型产权验证鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。