AquaLoRA: Toward White-box Protection for Customized Stable Diffusion Models via Watermark LoRA

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Feng, Weitao, Zhou, Wenbo, He, Jiyan, Zhang, Jie, Wei, Tianyi, Li, Guanlin, Zhang, Tianwei, Zhang, Weiming, Yu, Nenghai
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913356386926592
author Feng, Weitao
Zhou, Wenbo
He, Jiyan
Zhang, Jie
Wei, Tianyi
Li, Guanlin
Zhang, Tianwei
Zhang, Weiming
Yu, Nenghai
author_facet Feng, Weitao
Zhou, Wenbo
He, Jiyan
Zhang, Jie
Wei, Tianyi
Li, Guanlin
Zhang, Tianwei
Zhang, Weiming
Yu, Nenghai
contents Diffusion models have achieved remarkable success in generating high-quality images. Recently, the open-source models represented by Stable Diffusion (SD) are thriving and are accessible for customization, giving rise to a vibrant community of creators and enthusiasts. However, the widespread availability of customized SD models has led to copyright concerns, like unauthorized model distribution and unconsented commercial use. To address it, recent works aim to let SD models output watermarked content for post-hoc forensics. Unfortunately, none of them can achieve the challenging white-box protection, wherein the malicious user can easily remove or replace the watermarking module to fail the subsequent verification. For this, we propose \texttt{\method} as the first implementation under this scenario. Briefly, we merge watermark information into the U-Net of Stable Diffusion Models via a watermark Low-Rank Adaptation (LoRA) module in a two-stage manner. For watermark LoRA module, we devise a scaling matrix to achieve flexible message updates without retraining. To guarantee fidelity, we design Prior Preserving Fine-Tuning (PPFT) to ensure watermark learning with minimal impacts on model distribution, validated by proofs. Finally, we conduct extensive experiments and ablation studies to verify our design.
format Preprint
id arxiv_https___arxiv_org_abs_2405_11135
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle AquaLoRA: Toward White-box Protection for Customized Stable Diffusion Models via Watermark LoRA
Feng, Weitao
Zhou, Wenbo
He, Jiyan
Zhang, Jie
Wei, Tianyi
Li, Guanlin
Zhang, Tianwei
Zhang, Weiming
Yu, Nenghai
Cryptography and Security
Diffusion models have achieved remarkable success in generating high-quality images. Recently, the open-source models represented by Stable Diffusion (SD) are thriving and are accessible for customization, giving rise to a vibrant community of creators and enthusiasts. However, the widespread availability of customized SD models has led to copyright concerns, like unauthorized model distribution and unconsented commercial use. To address it, recent works aim to let SD models output watermarked content for post-hoc forensics. Unfortunately, none of them can achieve the challenging white-box protection, wherein the malicious user can easily remove or replace the watermarking module to fail the subsequent verification. For this, we propose \texttt{\method} as the first implementation under this scenario. Briefly, we merge watermark information into the U-Net of Stable Diffusion Models via a watermark Low-Rank Adaptation (LoRA) module in a two-stage manner. For watermark LoRA module, we devise a scaling matrix to achieve flexible message updates without retraining. To guarantee fidelity, we design Prior Preserving Fine-Tuning (PPFT) to ensure watermark learning with minimal impacts on model distribution, validated by proofs. Finally, we conduct extensive experiments and ablation studies to verify our design.
title AquaLoRA: Toward White-box Protection for Customized Stable Diffusion Models via Watermark LoRA
topic Cryptography and Security
url https://arxiv.org/abs/2405.11135