用于鲁棒时间序列水印的局部分词生成模型
A Locally Tokenized Generative Model for Robust Time-Series Watermarking
- Nanyang Technological University(南洋理工大学)
- Seoul National University(首尔大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对多变量时间序列水印受后编辑攻击可靠性失效的问题,提出L-VQVAE生成模型与LVQMark水印方法,在保留生成质量的同时稳定了攻击下的检测能力与误报行为。
AI中文摘要:
水印是生成模型来源溯源的核心工具,但其在多变量时间序列中的应用因后编辑攻击下的可靠性失效而受阻。研究表明,现有依赖全局耦合重编码的检测器会面临零假设分布的双向漂移:后编辑攻击可将非水印样本的z分数向任意方向偏移,使经干净校准的阈值失效。该不稳定性是重编码的固有属性,可靠检测要求每个恢复单元仅依赖有限时间邻域。据此,提出L-VQVAE(一种生成模型,每个离散标记由短连续窗口生成)和LVQMark(一种在该标记空间上的水印方法,结合logit偏置注入与攻击时检测的鲁棒重编码)。在金融、能源和神经成像领域的四个基准测试中,该方法在保留生成质量的同时,可稳定后编辑攻击下的检测能力与误报行为。
英文摘要:
Watermarking is a central tool for provenance in generative models, yet its application to multivariate time series remains hindered by reliability failures under post-editing attacks. We show that existing detectors, which rely on globally coupled re-encoding, suffer from bidirectional drift of the null distribution: post-editing attacks can shift the z-score of non-watermarked samples in either direction, invalidating clean-calibrated thresholds. We argue that this instability is a property of the re-encoding, and that reliable detection requires each recovered unit to depend only on a bounded temporal neighborhood. Guided by this principle, we propose L-VQVAE, a generative model in which each discrete token is produced from a short contiguous window, and LVQMark, a watermarking method over this token space that combines logit-bias injection with robust re-encoding for attack-time detection. Experiments on four benchmarks spanning finance, energy, and neuroimaging show that our approach preserves generation quality while stabilizing both detection power and false-positive behavior under post-editing attacks.