arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

HaloMark:一种适用于C2PA的嵌入向量水印的频谱阈值

HaloMark: A Spectral Threshold for Embedding-Vector Watermarking under C2PA

Tarun Sharma

arXiv 2608.08645首次发表:更新:

AI 中文总结

HaloMark是一种密码学绑定到C2PA清单的嵌入向量水印,通过将LSH承诺签名存入C2PA边车提升鲁棒性,在eff_rank(Sigma)/d≈0.19阈值下可抵御多种攻击,验证高效且经C2PA SDK验证。

AI 中文摘要

基础模型嵌入如今是主要的数据资产,但为图像和音频构建的内容溯源机制无法迁移到嵌入上。C2PA通过稳定的比特级或感知标识绑定到资产;而嵌入在正常使用中会因量化、投影、微调、窗口平均而发生形变,破坏任何固定哈希,因此不具备上述两种标识。我们提出HaloMark,一种密码学绑定到C2PA清单的嵌入向量水印。它由四个标准原语构成——块对角正交旋转、公共白化、依赖输入的LSH承诺,以及每个向量的随机数——围绕一个协议变更:生产者将LSH承诺c签名到C2PA边车中,验证者从清单中读取c而非重新计算。重新计算在白化下很脆弱,白化会在cos=0.96时翻转62%输入的承诺桶;读取签名的c将验证者的得分降至T = T_null + beta(A)*epsilon,因此安全性取决于单个标量beta,我们针对线性和非自适应攻击者对其进行严格界定,并针对自适应情况进行经验表征。我们在一个密钥下,针对拥有多项式数量干净/水印对且完全可见边车的攻击者,在8个基线和10个自适应攻击者(包括去噪自编码器去除)下进行评估。11个编码器在经验阈值eff_rank(Sigma)/d ≈ 0.19处分离:高于该阈值时,在我们全面扫描的3个编码器上,所有预算内攻击的检测AUROC保持在0.98或更高,其余编码器在单种子DAE去除下保持在0.965或更高;低于该阈值时,我们测试的所有变体均失败。该阈值为何是维度一致的仍有待研究。作为Qdrant准入过滤器部署时,验证者运行时间为284微秒,每个向量的边车为24字节,针对3个C2PA参考SDK绑定进行了端到端验证。

英文摘要

Foundation-model embeddings are now a primary data asset, but the content-provenance machinery built for images and audio does not transfer to them. C2PA binds to an asset with a stable bit-level or perceptual identity; embeddings have neither, since quantisation, projection, fine-tuning, and windowed averaging reshape them in normal use and break any fixed hash. We present HaloMark, a watermark for embedding vectors cryptographically bound to a C2PA manifest. It composes four standard primitives -- a block-diagonal orthogonal rotation, public whitening, an input-dependent LSH commitment, and a per-vector nonce -- around one protocol change: the producer signs the LSH commitment c into the C2PA sidecar, and the verifier reads c from the manifest instead of recomputing it. Recomputing is fragile under whitening, which flips the commitment bucket on 62% of inputs at cos = 0.96; reading the signed c reduces the verifier's score to T = T_null + beta(A)*epsilon, so security turns on a single scalar beta, which we bound rigorously for linear and non-adaptive attackers and characterise empirically for the adaptive case. We evaluate against an adversary holding polynomially many clean/watermarked pairs under one key with full sidecar visibility, across eight baselines and ten adaptive attackers including denoising-autoencoder removal. The eleven encoders separate at an empirical threshold eff_rank(Sigma)/d ~= 0.19: above it, detection AUROC stays at 0.98 or higher across every in-budget attack on the three encoders we sweep in full, and at 0.965 or higher under single-seed DAE removal on the rest; below it every variant we tested fails. Why the threshold is dimension-uniform is left open. Deployed as a Qdrant admission filter, the verifier runs at 284 us and 24 bytes of sidecar per vector, validated end-to-end against three C2PA reference-SDK bindings.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑