이미지 확산 모델의 효율적이고 강력하며 붕괴 방지 기능을 갖춘 워터마킹 기술
Efficient, Robust, and Anti-Collusion Fingerprinting of Image Diffusion Models
모델 워터마킹은 생성된 결과물에 사용자별 식별자(워터마크)를 포함시켜 생성형 텍스트-이미지(T2I) 모델의 지적 재산권을 보호하고 무단 배포를 방지하는 효과적인 방법으로 최근 주목받고 있습니다. 본 연구에서는 기존의 생성 모델 워터마킹 방식에 존재하는, 아직까지 탐구되지 않았던 중요한 취약점을 밝혀냅니다. 바로 이러한 방식들이 다수 공격자가 협력하여 워터마크를 제거하거나 가려내는 붕괴 공격에 대한 강건성을 결여하고 있다는 점입니다. 이러한 문제를 해결하기 위해, 본 연구는 T2I 모델에 대한 강력하고 붕괴 방지 기능을 갖춘 워터마킹 기술 개발의 첫걸음을 내딛습니다. 제안하는 방법은 비트 스트링 형태의 워터마크를 T2I 모델에 통합된 개인화 정규화 모듈(PNM)의 계수에 인코딩하여, 생성된 모든 이미지에서 워터마크를 안정적으로 복구할 수 있도록 합니다. 붕괴 공격을 방어하고 무단 모델 배포를 막기 위해, 우리는 손실 없는 함수 불변 변환 기반의 붕괴 방지 메커니즘을 도입합니다. 이 메커니즘은 협력 모델의 이미지 생성 품질을 현저히 저하시켜 실질적으로 사용할 수 없도록 만듭니다. 또한, 제안하는 방법은 개발자가 PNM을 재파라미터화하여 별도의 훈련 없이도 여러 개의 워터마크가 적용된 T2I 모델을 효율적으로 생성할 수 있도록 합니다. 더 나아가, 모델 수준 공격에 대한 강건성을 향상시키기 위한 최악의 경우 최적화 전략을 제시합니다. 실험 결과는 제안하는 방법이 다양한 T2I 이미지 생성 및 편집 작업에서 높은 충실도와 강건성을 달성하며, 워터마크 추출 정확도가 99.5%를 초과한다는 것을 보여줍니다. 기존 방법들과 비교했을 때, 본 연구에서는 처음으로 협력 공격에 대한 상당한 수준의 사전 방어 기능을 제공함으로써 협력 모델의 FID 값을 현저히 증가시키는 효과를 입증합니다.
Model fingerprinting, embedding user-specific identifiers (fingerprints) into generated outputs, has recently emerged as a popular solution to protect the intellectual property rights (IPR) of generative text-to-image (T2I) models and prevent unauthorized redistribution. In this work, we reveal a previously unexplored systematic vulnerability in existing generative model fingerprinting methods: they lack robustness against collusion attacks, where multiple attackers combine their models to remove or obscure the fingerprints. To address this issue, we take the first step towards a robust fingerprinting method for T2I models with anti-collusion capabilities. The proposed method encodes strings of bits, namely fingerprints, into the coefficients of a personalized normalization module (PNM) incorporated into T2I models, so that fingerprints can be reliably recovered from any generated image. To defend against collusion attacks and prevent unauthorized model redistribution, we introduce an anti-collusion mechanism based on lossless function-invariant parameter transformations. This mechanism significantly degrades the image generation quality of colluded models, making them effectively unusable. Moreover, our method allows developers to efficiently create multiple copies of fingerprinted T2I models by reparameterizing the PNM without the need for retraining. We also introduce a worst-case optimization strategy to improve robustness against model-level attacks. Our experiments demonstrate that the proposed method achieves high fidelity and robustness across multiple T2I image generation and editing tasks, with fingerprint extraction accuracy exceeding 99.5%. Compared with existing methods, our method demonstrates, for the first time, a notable proactive robustness to collusion attacks by significantly increasing the FID of colluded models.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.