arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于扩散模型的相关感知和高斯性保持的鲁棒潜在角水印

Correlation-Aware and Gaussianity-Preserving Robust Latent Angular Watermarking for Diffusion Models

Yebin Zheng, Haonan An, Guang Hua, Zhiping Lin, Yuguang Fang

arXiv 2607.22386首次发表:更新:

发表机构

Singapore Institute of Technology; City University of Hong Kong; Nanyang Technological University(新加坡理工学院; 香港城市大学; 南洋理工大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究扩散模型潜在域水印问题,提出潜在角水印(LAW)及变体LAW-M,通过对映角编码保持高斯性,解决现有方法易受攻击及相关性退化问题,理论上严格表征相关性退化并推导自相关结构。

AI 中文摘要

扩散模型的潜在域水印将水印直接嵌入到潜在先验中,对模型参数无侵入性且能与生成过程无缝集成。但现有方法因违反潜在高斯性或对潜在反演中的正常和恶意扰动敏感,易受水印检测或去除攻击,还存在违反独立同分布潜在条件导致潜在相关性退化和生成保真度损失的问题,虽已通过FID外部测量,但内部相关结构尚未严格表征。为解决这些问题,受各向同性高斯旋转不变性启发,我们提出潜在角水印(LAW),它在保持高斯性的同时将水印位编码为潜在元素不相交对之间的对映角(相对于参考对为±π/2)。对映编码最大化了位值之间的几何分离,我们证明解码角误差方差与潜在对的范数成比例,即var(Δϕ) ∝ 1/ρ²。我们还提出了幅度驱动变体LAW-M,它将水印位锚定在几何上最稳定的潜在维度中,进一步提高了鲁棒性。理论上,我们对诱导的相关性退化进行了严格表征,以封闭形式推导了水印潜在的自相关结构,并证明相关性局限于具有固定±π/4值的稀疏、结构化非对角元素集。

英文摘要

Latent domain watermarking for diffusion models embeds watermarks directly into the latent prior, enjoying non-intrusiveness to model parameters and seamless integration with the generation process. However, due to the violation of latent Gaussianity or sensitivity to normal and malicious perturbations during latent inversion, existing methods are prone to watermark detection or removal attacks. A further overlooked problem is the violation of the i.i.d. latent condition after watermarking, which leads to latent correlation degradation and generation fidelity loss. Although this has been externally measured by FID, the internal correlation structure has yet to be rigorously characterized. To address the above issues, and motivated by the rotation-invariant property of isotropic Gaussian, we propose \textit{Latent Angular Watermarking (LAW)}, which encodes watermark bits as antipodal angles ($\pmπ/2$ relative to a reference pair) between disjoint pairs of latent elements while preserving the Gaussianity. The antipodal ($π$-separation) encoding maximizes geometric separation between bit values, and we prove that the decoding angular-error variance is proportional to the norm of the latent pair, i.e., $\operatorname{var}(Δϕ) \propto 1/ρ^2$. We further propose a magnitude-driven variant, LAW-M, which anchors watermark bits in the most geometrically stable latent dimensions, yielding additional robustness gains. Theoretically, we provide a rigorous characterization of the induced correlation degradation, deriving in closed form the autocorrelation structure of the watermarked latent and proving that correlations are confined to a sparse, structured set of off-diagonal elements with fixed $\pmπ/4$ values.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑