arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向图像的可扩展黑盒模型归因

Scalable Black-Box Model Attribution for Images

Asaf Livne, Amir Jevnisek, Shai Avidan

arXiv 2608.15652首次发表:更新:

发表机构

Tel Aviv University(特拉维夫大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究提出轻量级CNN模型RPA,在黑盒设置下实现图像生成模型归因,准确率优于现有方法,具数据高效、成本独立、鲁棒性强等优势,还可通过少样本适配新模型。

AI 中文摘要

生成式模型的快速普及引发了模型归因问题:仅给定一张图像,能否确定它是由哪个模型生成的?现有方法已变得与其所针对的生成器一样复杂,其假设是更复杂的模型需要更复杂的归因器。我们证明这一假设不成立。RPA(Raw-Patch Attribution,原始补丁归因)在最严格的黑盒设置下,用一个轻量级CNN对图像进行归因。尽管结构简单,它仍能以更高的准确率归因更多模型:在25类DRAGON数据集上达到98.0%的准确率,在27类OpenFake数据集上达到92.9%的准确率;它具有数据高效的特点,运行成本与候选模型的数量无关;且对现实中图像经历的压缩、模糊和调整尺寸等干扰保持鲁棒性。针对闭集归因的训练得到了一个通用特征提取器:相同的表示无需监督即可恢复模型谱系,标记并分组未见过的生成器,且通过少样本适应而非重新训练即可适配新模型。

英文摘要

The rapid proliferation of generative models raises the model attribution problem: given only an image, can we determine which model produced it? We propose a lightweight CNN to solve this problem in a strict black box setting. The CNN operates on multiple image patches to handle varying image size and improve accuracy. It attributes more models at higher accuracy than prior work, reaching 98.9% on 25-class DRAGON and 95.0% on 27-class OpenFake; runs in a few milliseconds at a cost nearly independent of candidate-set size; and remains robust to transformations encountered in the wild. Beyond closed-set attribution, its learned representation serves as a reusable fingerprint backbone: it supports open-set rejection and few-shot enrollment, recovers model-family structure without lineage supervision, and groups images from unseen generators by source. Controlled ablations and causal perturbations show that its attribution decisions are driven by a spatially local, low-level signal that behaves as a generator-specific fingerprint.

CommentsProject page: https://asaf-livne.github.io/RPA/

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑