arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

FARI:用于扩散模型水印的鲁棒单步反演

FARI: Robust One-Step Inversion for Watermarking in Diffusion Models

Jindong Yang, Han Fang, Weiming Zhang, Nenghai Yu, Kejiang Chen

arXiv 2607.26723首次发表:更新:

发表机构

University of Science and Technology of China(中国科学技术大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出FARI框架,通过单步反演结合轻量级对抗LoRA微调,在提升扩散模型水印验证鲁棒性的同时大幅缩短推理时间,效率与性能均优于50步DDIM反演。

AI 中文摘要

基于反演的水印是对扩散模型生成图像进行认证的有前景方法,但实际应用受限于反演过程既缓慢又易出错。水印场景的主要挑战是抵御外部失真,而现有方法过度优化内部截断误差,且该误差随采样器步长增大,因此固有地局限于无法同时满足速度与鲁棒性需求的高函数评估次数(NFE)场景。本研究有两个关键发现:(i)反演轨迹的曲率显著低于正向生成路径,具有高度可压缩性,适用于低NFE近似;(ii)水印验证的反演中,速度与截断误差的权衡不那么关键,因为误差主要由外部失真主导。更快的反演器兼具双重优势:不仅效率更高,还能实现端到端对抗训练以直接针对鲁棒性,而原始冗长反演轨迹的该任务计算成本过高。基于此,我们提出FARI(Fast Asymmetric Robust Inversion,快速非对称鲁棒反演),即单步反演框架,搭配去噪器的轻量级对抗LoRA微调用于水印提取。尽管整合略微增加内部误差,但FARI在速度和鲁棒性上均有显著提升:在单张NVIDIA RTX A6000 GPU上进行约20分钟微调后,其水印验证鲁棒性超过50步DDIM反演,同时大幅缩短推理时间。代码与预训练模型可在指定URL获取。

英文摘要

Inversion-based watermarking is a promising approach to authenticate diffusion-generated images, yet practical use is bottlenecked by inversion that is both slow and error-prone. While the primary challenge in the watermarking setting is robustness against external distortions, existing approaches over-optimize internal truncation error, and because that error scales with the sampler step size, they are inherently confined to high-NFE (number of function evaluations) regimes that cannot meet the dual demands of speed and robustness. In this work, we have two key observations: (i) the inversion trajectory has markedly lower curvature than the forward generation path does, making it highly compressible and amenable to low-NFE approximation; and (ii) in inversion for watermark verification, the trade-off between speed and truncation error is less critical, since external distortions dominate the error. A faster inverter provides a dual benefit: it is not only more efficient, but it also enables end-to-end adversarial training to directly target robustness, a task that is computationally prohibitive for the original, lengthy inversion trajectories. Building on this, we propose \textbf{FARI} (\textbf{F}ast \textbf{A}symmetric \textbf{R}obust \textbf{I}nversion), a one-step inversion framework paired with lightweight adversarial LoRA fine-tuning of the denoiser for watermark extraction. While consolidation slightly increases internal error, FARI delivers large gains in both speed and robustness: with approximately 20 minutes of fine-tuning on a single NVIDIA RTX A6000 GPU, it surpasses 50-step DDIM inversion on watermark-verification robustness while dramatically reducing inference time. Code and pretrained models are available at https://github.com/0xD009/FARI.

CommentsAccepted by ICLR 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑