ChatPaper.aiChatPaper

无训练自回归图像生成水印技术

Training-Free Watermarking for Autoregressive Image Generation

May 20, 2025
作者: Yu Tong, Zihao Pan, Shuai Yang, Kaiyang Zhou
cs.AI

摘要

隐形图像水印技术能够有效保护图像版权,防止视觉生成模型被恶意滥用。然而,现有的生成式水印方法主要针对扩散模型设计,而对于自回归图像生成模型的水印技术研究仍显不足。为此,我们提出了IndexMark,一种无需训练的自回归图像生成模型水印框架。IndexMark的灵感来源于码本冗余特性:用相似索引替换自回归生成的索引,对图像视觉差异影响微乎其微。IndexMark的核心在于一种简洁高效的匹配-替换方法,该方法基于令牌相似度从码本中精心挑选水印令牌,并通过令牌替换促进水印令牌的使用,从而在不影响图像质量的前提下嵌入水印。水印验证通过计算生成图像中水印令牌的比例实现,并借助索引编码器进一步提升验证精度。此外,我们还引入了一种辅助验证方案,以增强对裁剪攻击的鲁棒性。实验表明,IndexMark在图像质量和验证准确性方面均达到了业界领先水平,并对裁剪、噪声、高斯模糊、随机擦除、色彩抖动及JPEG压缩等多种干扰表现出良好的鲁棒性。
English
Invisible image watermarking can protect image ownership and prevent malicious misuse of visual generative models. However, existing generative watermarking methods are mainly designed for diffusion models while watermarking for autoregressive image generation models remains largely underexplored. We propose IndexMark, a training-free watermarking framework for autoregressive image generation models. IndexMark is inspired by the redundancy property of the codebook: replacing autoregressively generated indices with similar indices produces negligible visual differences. The core component in IndexMark is a simple yet effective match-then-replace method, which carefully selects watermark tokens from the codebook based on token similarity, and promotes the use of watermark tokens through token replacement, thereby embedding the watermark without affecting the image quality. Watermark verification is achieved by calculating the proportion of watermark tokens in generated images, with precision further improved by an Index Encoder. Furthermore, we introduce an auxiliary validation scheme to enhance robustness against cropping attacks. Experiments demonstrate that IndexMark achieves state-of-the-art performance in terms of image quality and verification accuracy, and exhibits robustness against various perturbations, including cropping, noises, Gaussian blur, random erasing, color jittering, and JPEG compression.

Summary

AI-Generated Summary

PDF111May 21, 2025