AGMark: 어텐션 기반 동적 워터마킹 - 대규모 비전-언어 모델을 위한 방법
AGMark: Attention-Guided Dynamic Watermarking for Large Vision-Language Models
워터마킹은 대규모 비전-언어 모델(LVLM)에서 콘텐츠 추적 가능성과 지적 재산 보호를 위한 핵심적인 솔루션으로 부상했습니다. 그러나 비전 정보에 독립적인 워터마크는 시각적으로 관련 없는 토큰을 도입하고, 무분별한 유사 난수 편향을 강제하여 시각적 연관성을 방해할 수 있습니다. 또한, 현재의 비전 특화 워터마크는 비전에서 중요한 가중치를 정적으로, 일회적으로 추정하며, 보호될 토큰의 비율을 결정할 때 가중치 분포 밀도를 고려하지 않습니다. 이러한 설계는 생성 과정에서의 시각적 의존성의 동적인 변화를 고려하지 못하며, 결과적으로 생성 과정 후반부에 품질이 낮은 토큰을 생성할 수 있습니다. 이러한 문제점을 해결하기 위해, 우리는 어텐션 기반 동적 워터마킹(AGMark)이라는 새로운 프레임워크를 제안합니다. AGMark는 검출 가능한 신호를 임베딩하면서 시각적 충실도를 엄격하게 유지합니다. AGMark는 각 디코딩 단계에서 어텐션 가중치를 기반으로 시각적 관련성을 나타내는 중요한 증거를 동적으로 식별하고, 맥락 인지 일관성 단서를 함께 고려하여, 보다 적응적이고 잘 조정된 증거-가중치 분포를 얻습니다. 또한, 불확실성 인식(토큰 엔트로피)과 증거 교정(가중치 밀도)을 함께 고려하여 의미적으로 중요한 토큰의 비율을 결정함으로써, 불필요한 토큰을 방지하기 위한 적응적인 어휘 분할을 가능하게 합니다. 실험 결과는 AGMark가 기존 방법보다 우수하며, 생성 품질을 향상시키고, 특히 생성 과정 후반 단계에서 시각적 의미 충실도를 크게 향상시킨다는 것을 확인했습니다. 이 프레임워크는 높은 검출 정확도(최소 99.36% AUC)와 강력한 공격 방어 능력(최소 88.61% AUC)을 유지하면서 추론 효율성을 저하시키지 않아, 신뢰성을 유지하는 멀티모달 워터마킹의 새로운 기준을 제시합니다.
Watermarking has emerged as a pivotal solution for content traceability and intellectual property protection in Large Vision-Language Models (LVLMs). However, vision-agnostic watermarks may introduce visually irrelevant tokens and disrupt visual grounding by enforcing indiscriminate pseudo-random biases. Additionally, current vision-specific watermarks rely on a static, one-time estimation of vision critical weights and ignore the weight distribution density when determining the proportion of protected tokens. This design fails to account for dynamic changes in visual dependence during generation and may introduce low-quality tokens in the long tail. To address these challenges, we propose Attention-Guided Dynamic Watermarking (AGMark), a novel framework that embeds detectable signals while strictly preserving visual fidelity. At each decoding step, AGMark first dynamically identifies semantic-critical evidence based on attention weights for visual relevance, together with context-aware coherence cues, resulting in a more adaptive and well-calibrated evidence-weight distribution. It then determines the proportion of semantic-critical tokens by jointly considering uncertainty awareness (token entropy) and evidence calibration (weight density), thereby enabling adaptive vocabulary partitioning to avoid irrelevant tokens. Empirical results confirm that AGMark outperforms conventional methods, observably improving generation quality and yielding particularly strong gains in visual semantic fidelity in the later stages of generation. The framework maintains highly competitive detection accuracy (at least 99.36\% AUC) and robust attack resilience (at least 88.61\% AUC) without sacrificing inference efficiency, effectively establishing a new standard for reliability-preserving multi-modal watermarking.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.