DIAGNOSIS: Detecting Unauthorized Data Usages in Text-to-image Diffusion Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Zhenting, Chen, Chen, Lyu, Lingjuan, Metaxas, Dimitris N., Ma, Shiqing
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909163668373504
author Wang, Zhenting
Chen, Chen
Lyu, Lingjuan
Metaxas, Dimitris N.
Ma, Shiqing
author_facet Wang, Zhenting
Chen, Chen
Lyu, Lingjuan
Metaxas, Dimitris N.
Ma, Shiqing
contents Recent text-to-image diffusion models have shown surprising performance in generating high-quality images. However, concerns have arisen regarding the unauthorized data usage during the training or fine-tuning process. One example is when a model trainer collects a set of images created by a particular artist and attempts to train a model capable of generating similar images without obtaining permission and giving credit to the artist. To address this issue, we propose a method for detecting such unauthorized data usage by planting the injected memorization into the text-to-image diffusion models trained on the protected dataset. Specifically, we modify the protected images by adding unique contents on these images using stealthy image warping functions that are nearly imperceptible to humans but can be captured and memorized by diffusion models. By analyzing whether the model has memorized the injected content (i.e., whether the generated images are processed by the injected post-processing function), we can detect models that had illegally utilized the unauthorized data. Experiments on Stable Diffusion and VQ Diffusion with different model training or fine-tuning methods (i.e, LoRA, DreamBooth, and standard training) demonstrate the effectiveness of our proposed method in detecting unauthorized data usages. Code: https://github.com/ZhentingWang/DIAGNOSIS.
format Preprint
id arxiv_https___arxiv_org_abs_2307_03108
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle DIAGNOSIS: Detecting Unauthorized Data Usages in Text-to-image Diffusion Models
Wang, Zhenting
Chen, Chen
Lyu, Lingjuan
Metaxas, Dimitris N.
Ma, Shiqing
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
Recent text-to-image diffusion models have shown surprising performance in generating high-quality images. However, concerns have arisen regarding the unauthorized data usage during the training or fine-tuning process. One example is when a model trainer collects a set of images created by a particular artist and attempts to train a model capable of generating similar images without obtaining permission and giving credit to the artist. To address this issue, we propose a method for detecting such unauthorized data usage by planting the injected memorization into the text-to-image diffusion models trained on the protected dataset. Specifically, we modify the protected images by adding unique contents on these images using stealthy image warping functions that are nearly imperceptible to humans but can be captured and memorized by diffusion models. By analyzing whether the model has memorized the injected content (i.e., whether the generated images are processed by the injected post-processing function), we can detect models that had illegally utilized the unauthorized data. Experiments on Stable Diffusion and VQ Diffusion with different model training or fine-tuning methods (i.e, LoRA, DreamBooth, and standard training) demonstrate the effectiveness of our proposed method in detecting unauthorized data usages. Code: https://github.com/ZhentingWang/DIAGNOSIS.
title DIAGNOSIS: Detecting Unauthorized Data Usages in Text-to-image Diffusion Models
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2307.03108