Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Müller, Andreas, Lukovnikov, Denis, Thietke, Jonas, Fischer, Asja, Quiring, Erwin
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866912418540552192
author Müller, Andreas
Lukovnikov, Denis
Thietke, Jonas
Fischer, Asja
Quiring, Erwin
author_facet Müller, Andreas
Lukovnikov, Denis
Thietke, Jonas
Fischer, Asja
Quiring, Erwin
contents Integrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. Specifically, we design two watermark forgery attacks. The first imprints a targeted watermark into real images by manipulating the latent representation of an arbitrary image in an unrelated LDM to get closer to the latent representation of a watermarked image. We also show that this technique can be used for watermark removal. The second attack generates new images with the target watermark by inverting a watermarked image and re-generating it with an arbitrary prompt. Both attacks just need a single reference image with the target watermark. Overall, our findings question the applicability of semantic watermarks by revealing that attackers can easily forge or remove these watermarks under realistic conditions.
format Preprint
id arxiv_https___arxiv_org_abs_2412_03283
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models
Müller, Andreas
Lukovnikov, Denis
Thietke, Jonas
Fischer, Asja
Quiring, Erwin
Cryptography and Security
Artificial Intelligence
Computer Vision and Pattern Recognition
Integrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. Specifically, we design two watermark forgery attacks. The first imprints a targeted watermark into real images by manipulating the latent representation of an arbitrary image in an unrelated LDM to get closer to the latent representation of a watermarked image. We also show that this technique can be used for watermark removal. The second attack generates new images with the target watermark by inverting a watermarked image and re-generating it with an arbitrary prompt. Both attacks just need a single reference image with the target watermark. Overall, our findings question the applicability of semantic watermarks by revealing that attackers can easily forge or remove these watermarks under realistic conditions.
title Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models
topic Cryptography and Security
Artificial Intelligence
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2412.03283