arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

AngelFingerprint:用于文本引导图像编辑的可追溯、可解释且白盒隐身的水印

AngelFingerprint: A Traceable, Explainable, and White-Box Stealthy Watermark for Text-Guided Image Editing

Bo-Han Kung, Futa Waseda, Ching-Chun Chang, Isao Echizen, Shang-Tse Chen

arXiv 2609.04709首次发表:更新:

发表机构

National Taiwan University; National Institute of Informatics(台湾大学; 信息学研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对文本引导图像编辑的虚假信息问题,提出AngelFingerprint水印框架,通过集成LoRA嵌入CLIP文本嵌入,结合速度对齐锚点和频率滤波器,在MagicBrush数据集上200路提示检索top-1准确率达86%,优于提示反转的20%。

AI 中文摘要

文本引导的扩散编辑引发了虚假信息方面的担忧,因此可靠的图像来源追溯至关重要。尽管水印通常用于此目的,但大多数方法带有固定ID,无法解释发生了什么更改以及由哪个提示生成。此外,在开源白盒访问下,攻击者可以轻松定位并移除作为单独模块添加的水印。针对该场景,我们提出了AngelFingerprint,这是一种新颖的水印框架,确保编辑可追溯性、可解释性和白盒隐身性。它将LoRA(低秩适配)集成到扩散模型中,以将编辑提示的CLIP文本嵌入直接嵌入模型权重中。然后,提取器可仅从图像像素中恢复此嵌入。这种语义有效载荷可解释编辑内容,而权重集成设计使其即使在完全白盒访问下也难以检测和隔离。两种技术实现了这一点:速度对齐锚点,可保持编辑质量;以及专门设计的频率滤波器,可使水印不可察觉但仍可恢复且具有鲁棒性。在MagicBrush数据集上,我们的提取器在200路提示检索中达到了86%的top-1准确率,而提示反转方法仅为20%。

英文摘要

Text-guided diffusion editing raises disinformation concerns, making reliable image provenance essential. While watermarks are commonly used for this purpose, most methods carry a fixed ID that cannot explain what was changed and which prompt produced it. Furthermore, under open-source white-box access, attackers can easily locate and remove watermarks added as separate modules. Targeting this setting, we propose AngelFingerprint, a novel watermarking framework ensuring edit traceability, explainability, and white-box stealthiness. It integrates a LoRA into the diffusion model to embed the editing prompt's CLIP text embedding directly into the model's weights. An extractor then recovers this embedding from the image pixels alone. This semantic payload explains the edit, while the weight-integrated design makes it hard to detect and isolate even under full white-box access. Two techniques make this possible: a velocity-alignment anchor that preserves edit quality, and a specially designed frequency filter that keeps the watermark imperceptible yet recoverable and robust. On the MagicBrush dataset, our extractor achieves $86\%$ top-1 accuracy in a 200-way prompt retrieval, versus $20\%$ for prompt inversion.

Comments15 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑