arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

生成式编辑下的潜在水印:检测存活的基准与分析

Latent Watermarks under Generative Editing: A Benchmark and Analysis of Detection Survival

Sung Ju Lee, Nam Ik Cho

arXiv 2610.09702首次发表:更新:

发表机构

Seoul National University(首尔大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究基准测试了生成式编辑下八种潜在水印方法的检测存活率,发现编辑主要影响Tree-Ring,且干净分数分离度($d'$)是预测存活的有效诊断指标。

AI 中文摘要

普通的基于提示的编辑可能导致潜在水印检测失败,而无需显式针对水印进行操作。我们在四个生成骨干网络、四种编辑强度、五个语义类别上,对八种水印方法与五种编辑器进行了基准测试,并进行了编辑有效性和阈值检查。将编辑与七种后续失真分离,结果显示编辑本身主要区分了Tree-Ring,而添加的失真则暴露了更广泛的检测存活谱系。顺序编辑揭示了第二个隐藏差异:分数分离度可能下降,而检测率仍接近其上限。跨方法来看,标准化的干净分数分离度($d'$)组织了复合存活层级,而空间重叠在预测仅编辑存活方面,除了干净可检测性之外,贡献甚微。两种方法中的嵌入强度干预将更高的干净分离度与更高的编辑后分离度联系起来。在HSTR中,边际对比为正,而在匹配的干净分离度下,角度布局对比仍未解决。总之,结果分解和连续分离度揭示了聚合TPR所隐藏的差异。在主要操作点和替代复合权重下,方法层级在阈值重新校准下保持稳定。因此,干净$d'$在此基准内是一个有用的经验诊断指标,但对未见方法的迁移表现不一。代码和支持工件计划另行发布。

英文摘要

Ordinary prompt-based editing can cause latent watermark detection to fail without explicitly targeting the watermark. We benchmark eight watermark methods against five editors across four generative backbones, four editing strengths, and five semantic categories, with edit-validity and threshold checks. Separating editing from seven subsequent distortions reveals that editing alone primarily distinguishes Tree-Ring, while added distortions expose a broader spectrum of detection survival. Sequential edits reveal a second hidden difference: score separation can decline while detection rates remain near their ceiling. Across methods, standardized clean score separation ($d'$) organizes composite-survival tiers, whereas spatial overlap adds little to predicting edit-only survival beyond clean detectability. Embedding-strength interventions in two methods link higher clean separation to higher post-edit separation. In HSTR, the margin contrast is positive, while the angular layout contrast at matched clean separation remains unresolved. Together, outcome decomposition and continuous separation expose differences hidden by aggregate TPR. Method tiers are stable under threshold recalibration at the main operating points and alternative composite weights. Clean $d'$ is thus a useful empirical diagnostic within this benchmark, with mixed transfer to unseen methods. Code and supporting artifacts are planned for a separate release.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑