发表机构
Hallym University(翰林大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文研究通过预训练生成器进行潜空间水印的信息论极限,推导容量区域并刻画密钥分配,同时分析再生攻击下的鲁棒性及容量衰减。
AI 中文摘要
我们研究通过预训练生成器进行潜空间水印,该生成器使用一个规定的潜变量到输出的随机映射,称为渲染器。水印编码器使用消息和密钥选择潜变量输入。对于每条消息和语义上下文,发布的输出必须精确地具有期望的条件输出分布。对于有限字母表,我们推导了速率-密钥内界和外界,并刻画了通过规定的潜变量接口实现水印通信所需的编码和协调要求。当生成器的目标输出分布通过渲染器唯一确定相应的潜变量输入分布时,一个加强的逆命题给出了容量区域;同一区域也支配着对预训练潜变量分布的显式保持。我们将分析扩展到一般联合高斯模型,并识别出潜变量的一个充分统计量,该统计量同时捕获了生成输出中可用的水印承载信息以及保持其目标分布所需的潜变量协调。对于向量高斯模型,我们进一步刻画了密钥资源在所得模态间的最优分配。最后,我们转向一个在生成式水印中特别自然的新兴鲁棒性威胁:对手可以重新生成已发布的样本,以获得相同底层内容的新实现,同时衰减或破坏嵌入的水印。我们将这一鲁棒性轴纳入我们的框架,并刻画了当语义上下文对编码器已知但对检测器隐藏,而再生攻击可能依赖于该上下文时,标量高斯模型的单遍复合容量。将分析扩展到多轮重复的规范再生,我们刻画了由此产生的水印容量衰减。
英文摘要
We study latent-space watermarking through a pretrained generator using a prescribed latent-to-output stochastic mapping, called the renderer. A watermark encoder selects the latent input using a message and secret key. For every message and semantic context, the released output must have exactly the desired conditional output distribution. For finite alphabets, we derive rate--key inner and outer bounds and characterize the coding and coordination requirements for realizing watermark communication through the prescribed latent interface. When the target output distribution of the generator uniquely determines the corresponding latent input distribution through the renderer, a strengthened converse yields the capacity region; the same region governs explicit preservation of the pretrained latent distribution. We extend the analysis to general jointly Gaussian models and identify a sufficient statistic of the latent that captures both the watermark-bearing information available at the generated output and the latent coordination required to preserve its target distribution. For the vector Gaussian model, we further characterize the optimal allocation of the secret-key resource across the resulting modes. Finally, we turn to an emerging robustness threat that is particularly natural in generative watermarking: an adversary can regenerate the released sample to obtain a fresh realization of the same underlying content while attenuating or destroying the embedded watermark. We incorporate this robustness axis into our framework and characterize the one-pass compound capacity of the scalar Gaussian model when the semantic context is known to the encoder but hidden from the detector, while the regeneration attack may depend on that context. Extending the analysis to multiple rounds of repeated canonical regeneration, we characterize the resulting watermark-capacity decay.
CommentsSubmitted to the IEEE Transactions on Information Theory for possible publication