Embedding Watermarks in Diffusion Process for Model Intellectual Property Protection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Jijia, Peng, Sen, Jia, Xiaohua
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917822278402048
author Yang, Jijia
Peng, Sen
Jia, Xiaohua
author_facet Yang, Jijia
Peng, Sen
Jia, Xiaohua
contents In practical application, the widespread deployment of diffusion models often necessitates substantial investment in training. As diffusion models find increasingly diverse applications, concerns about potential misuse highlight the imperative for robust intellectual property protection. Current protection strategies either employ backdoor-based methods, integrating a watermark task as a simpler training objective with the main model task, or embedding watermarks directly into the final output samples. However, the former approach is fragile compared to existing backdoor defense techniques, while the latter fundamentally alters the expected output. In this work, we introduce a novel watermarking framework by embedding the watermark into the whole diffusion process, and theoretically ensure that our final output samples contain no additional information. Furthermore, we utilize statistical algorithms to verify the watermark from internally generated model samples without necessitating triggers as conditions. Detailed theoretical analysis and experimental validation demonstrate the effectiveness of our proposed method.
format Preprint
id arxiv_https___arxiv_org_abs_2410_22445
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Embedding Watermarks in Diffusion Process for Model Intellectual Property Protection
Yang, Jijia
Peng, Sen
Jia, Xiaohua
Computer Vision and Pattern Recognition
Cryptography and Security
In practical application, the widespread deployment of diffusion models often necessitates substantial investment in training. As diffusion models find increasingly diverse applications, concerns about potential misuse highlight the imperative for robust intellectual property protection. Current protection strategies either employ backdoor-based methods, integrating a watermark task as a simpler training objective with the main model task, or embedding watermarks directly into the final output samples. However, the former approach is fragile compared to existing backdoor defense techniques, while the latter fundamentally alters the expected output. In this work, we introduce a novel watermarking framework by embedding the watermark into the whole diffusion process, and theoretically ensure that our final output samples contain no additional information. Furthermore, we utilize statistical algorithms to verify the watermark from internally generated model samples without necessitating triggers as conditions. Detailed theoretical analysis and experimental validation demonstrate the effectiveness of our proposed method.
title Embedding Watermarks in Diffusion Process for Model Intellectual Property Protection
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2410.22445