人工智能生成内容模型的数字水印技术研究进展
网络出版日期: 2024-05-18
基金资助
国家自然科学基金(U20B2051,U22B2047,U1936214)
版权
Survey on digital watermarking technology for artificial intelligence generated content models
Online published: 2024-05-18
Copyright
人工智能(AI)正在改变世界,人工智能生成内容(AIGC)是当前最前沿的技术之一。探讨人工智能生成内容的演变历程,介绍从AI到AIGC的技术变迁,讨论AIGC引发的相关问题和挑战以及应对策略。同时,关注全球范围内的法律法规和国际动向,分析不同国家和组织在人工智能监管方面采取的举措,尤其是中国在全球AI治理中的贡献。着重介绍的是AIGC模型的数字水印(Digital Watermarking)技术。数字水印已有多年发展的历史,在多媒体确权、防伪、认证等方面发挥了重要作用,随着AIGC的兴起,数字水印在模型保护、内容溯源、样本保护等方面又开始发挥新的作用。关于AIGC模型的数字水印技术研究进展的介绍,将为理解AIGC安全领域的发展提供新的视角维度,为研究AIGC领域的应用实践提供参考。
郭钊均 , 李美玲 , 周杨铭 , 彭万里 , 李晟 , 钱振兴 , 张新鹏 . 人工智能生成内容模型的数字水印技术研究进展[J]. 网络空间安全科学学报, 2024 , 2(1) : 13 -39 . DOI: 10.20172/j.issn.2097-3136.240102
Artificial intelligence (AI) is changing the world, and artificial intelligence generated content (AI Generated Content, AIGC) is currently one of the most cutting-edge technology. The evolution of AIGC, introduce the technological changes from AI to AIGC, and discuss the related problems and challenges caused by AIGC as well as coping strategies. At the same time, this study will also focus on the laws and regulations and international trends on a global scale, analyze the initiatives taken by different countries and organizations in AI regulation, especially China's contribution in global AI governance. The Digital Watermarking (DW) technology of the AIGC model is introduced. Digital Watermarking has been developed for many years and has played an important role in multimedia rights confirmation, anti-counterfeiting, authentication, etc. With the rise of AIGC, Digital Watermarking has begun to play a new role in model protection, content traceability and sample protection. The introduction on the research progress of digital watermarking technology for AIGC model will provide a new perspective dimension for understanding the development of AIGC security field, and provide a reference for researching the application practice in the field of AIGC.
表 1 关于人工智能治理的监管法规对比Table 1 Comparison of regulatory statutes on AI governance |
| 国家/地区 | 重点方向 | 重要措施 | 日期/年 |
| 中国 | 强调政府引导和安全监管 | 《生成式人工智能服务管理暂行办法》 《生成式人工智能服务安全基本要求》 | 2023 |
| 美国 | 强调技术创新和自由市场 | 拜登签署首个生成式AI监管规定 | 2023 |
| 欧盟 | 聚焦隐私保护和伦理道德 | 《人工智能法案》 | 2023 |
| 1 |
VASWANI A,SHAZEER N,PARMAR N,et al. Attention is all you need[J]. Advances in Neural Information Processing Systems 30,2017.
|
| 2 |
OUYANG L,WU J,JIANG X,et al. Training language models to follow instructions with human feedback[EB]. arXiv preprint arXiv:2203. 02155,2022.
|
| 3 |
ROMBACH R,BLATTMANN A,LORENZ D,et al. High-resolution image synthesis with latent diffusion models[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR),2022:10684-10695.
|
| 4 |
DERNER E, BATISTIČ K. Beyond the safeguards: exploring the security risks of ChatGPT[J]. arXiv preprint arXiv:, 2305, 08005
|
| 5 |
GOODFELLOW I,POUGET-ABADIE J,MIRZA M,et al. Generative adversarial nets[C]//Advances in Neural Information Processing Systems. 2014:2672-2680.
|
| 6 |
RADFORD A, METZ L, CHINTALA S. Unsupervised representation learning with deep convolutional generative adversarial networks[J]. arXiv preprint arXiv:, 1511, 06434, 2015.
|
| 7 |
KARRAS T, AILA T, LAINE S, et al. Progressive growing of GANs for improved quality, stability, and variation[J]. arXiv preprint arXiv:, 1710, 10196, 2017.
|
| 8 |
KARRAS T,LAINE S,AILA T. A style-based generator architecture for generative adversarial networks[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2019:4401-4410.
|
| 9 |
KANG M,SHIN J,PARK J. StudioGAN: A taxonomy and benchmark of GANs for image synthesis[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence,2023,45:15725-15742.
|
| 10 |
PAN X,TEWARI A,LEIMKÜHLER T,et al. Drag your GAN:Interactive point-based manipulation on the generative image manifold[C]//ACM SIGGRAPH 2023 Conference Proceedings,2023:1-11.
|
| 11 |
HO J, JAIN A, ABBEEL P. Denoising diffusion probabilistic models[J]. Advances in Neural Information Processing Systems, 2020, 33, 6840- 6851.
|
| 12 |
SOHL-DICKSTEIN J,WEISS E,MAHESWARANATHAN N,et al. Deep unsupervised learning using nonequilibrium thermodynamics[C]//International Conference on Machine Learning. PMLR,2015:2256-2265.
|
| 13 |
CAO H,TAN C,GAO Z,et al. A survey on generative diffusion models[J]. IEEE Transactions on Knowledge and Data Engineering,2024:1-20.
|
| 14 |
KINGMA D P, SALIMANS T, JOZEFOWICZ R, et al. Improved variational inference with inverse autoregressive flow[J]. Advances in Neural Information Processing Systems, 2016, 29, 4743- 4751.
|
| 15 |
WESTERLUND M. The emergence of deepfake technology: A review[J]. Technology innovation Management Review, 2019, 9 (11): 40- 53.
|
| 16 |
THIES J,ZOLLHOFER M,STAMMINGER M,et al. Face2face:real-time face capture and reenactment of RGB videos[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition,2016:2387-2395.
|
| 17 |
NIRKIN Y,KELLER Y,HASSNER T. FsGAN:Subject agnostic face swapping and reenactment[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2019:7184-7193.
|
| 18 |
SIAROHIN A,WOODFORD O J,REN J,et al. Motion representations for articulated animation[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2021:13653-13662.
|
| 19 |
ZHANG C,ZHAO Y,HUANG Y,et al. Facial:Synthesizing dynamic talking face with implicit attribute learning[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2021:3867-3876.
|
| 20 |
LI L, BAO J, YANG H, et al. Faceshifter: Towards high fidelity and occlusion aware face swapping[J]. arXiv preprint arXiv:, 1912, 13457, ,2019.
|
| 21 |
CHEN R,CHEN X,NI B,et al. Simswap:An efficient framework for high fidelity face swapping[C]//Proceedings of the 28th ACM International Conference on Multimedia,2020:2003-2011.
|
| 22 |
ZENG H,ZHANG W,FAN C,et al. Flowface:Semantic flow-guided shape-aware face swapping[C]//Proceedings of the AAAI Conference on Artificial Intelligence,2023,37(3):3367-3375.
|
| 23 |
ZHU Y, LIU H, SONG Y, et al. One model to edit them all: free-form text-driven image manipulation with semantic modulations[J]. Advances in Neural Information Processing Systems, 2022, 35, 25146- 25159.
|
| 24 |
KIM H,CHOI Y,KIM J,et al. Exploiting spatial dimensions of latent in GAN for real-time image editing[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2021:852-861.
|
| 25 |
SAUER A,SCHWARZ K,GEIGER A. Stylegan-xl:Scaling stylegan to large diverse datasets[C]//ACM SIGGRAPH 2022 Conference Proceedings,2022:1-10.
|
| 26 |
SAUER A, KARRAS T, LAINE S, et al. Stylegan-t: Unlocking the power of GANs for fast large-scale text-to-image synthesis[J]. arXiv preprint arXiv:, 2301, 09515, ,2023.
|
| 27 |
YU P,XIA Z,FEI J,et al. A survey on deepfake video detection[J]. Iet Biometrics,2021,10(6):607-624.
|
| 28 |
KWOK A O, KOH S G. Deepfake: a social construction of technology perspective[J]. Current Issues in Tourism, 2021, 24 (13): 1798- 1802.
|
| 29 |
AKHTAR Z. Deepfakes generation and detection:A short survey[J]. Journal of Imaging,2023,9(1):18.
|
| 30 |
HUANG H,WANG Y,CHEN Z,et al. CMUA-watermark:a cross-model universal adversarial watermark for combating deepfakes[EB]. arXiv preprint arXiv:2105. 10872,2021.
|
| 31 |
SUN P,QI H,LI Y,et al. Faketracer:proactively defending against face-swap deepfakes via implanting traces in training[EB]. arXiv preprint arXiv:2307. 14593,2023.
|
| 32 |
AFCHAR D,NOZICK V,YAMAGISHI J,et al. MesoNet:a compact facial video forgery detection network[C]//2018 IEEE International Workshop on Information Forensics and Security (WIFS). IEEE,2018.
|
| 33 |
LI Y,LYU S. Exposing deepfake videos by detecting face warping artifacts [EB]. arXiv preprint arXiv:1811. 00656,2019.
|
| 34 |
RÖSSLER A,COZZOLINO D,VERDOLIVA L,et al. FaceForensics++:learning to detect manipulated facial images[EB]. arXiv preprint arXiv:1901. 08971,2019.
|
| 35 |
KARRAS T,LAINE S,AILA T. A style-based generator architecture for generative adversarial networks[EB]. arXiv preprint arXiv:1812. 04948,2019.
|
| 36 |
RADFORD A,NARASIMHAN K,SALIMANS T,et al. Improving language understanding by generative pretraining[J/OL].
|
| 37 |
RADFORD A,WU J,CHILD R,et al. Language models are unsupervised multitask learners[J]. OpenAI blog,2019,1(8):9.
|
| 38 |
BROWN T, MANN B, RYDER N, et al. Language models are few-shot learners[J]. Advances in Neural Information Processing Systems, 2020, 33, 1877- 1901.
|
| 39 |
KIRILLOV A, MINTUN E, RAVI N, et al. Segment anything[J]. [EB]. arXiv preprint arXiv:, 2304, 02643, 2023.
|
| 40 |
XI T,SUN Y,YU D,et al. UFO:unified feature optimization[C]//European Conference on Computer Vision,2022:472-488.
|
| 41 |
DHARIWAL P, NICHOL A. Diffusion models beat GANs on image synthesis[J]. Advances in Neural Information Processing Systems, 2021, 34, 8780- 8794.
|
| 42 |
ZHANG L,RAO A,AGRAWALA M. Adding conditional control to text-to-image diffusion models[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2023:3836-3847.
|
| 43 |
RADFORD A,KIM J W,HALLACY C,et al. Learning transferable visual models from natural language supervision[C]//International Conference On Machine Learning,2021:8748-8763.
|
| 44 |
LUO H,JI L,ZHONG M,et al. Clip4clip:An empirical study of clip for end to end video clip retrieval and captioning[J]. Neurocomputing,2022,508:293-304.
|
| 45 |
WANG M, XING J, LIU Y. Actionclip: a new paradigm for video action recognition[J]. [EB]. arXiv preprint arXiv:, 2109, 08472, 2021.
|
| 46 |
RAMESH A,PAVLOV M,GOH G,et al. Zero-shot text-to-image generation[C] //International Conference on Machine Learning. 2021:8821-8831.
|
| 47 |
PUSHPA MALA S, JAYADEVAPPA D, EZHILARASAN K. Digital image watermarking techniques: a review[J]. Int J Comput Sci Secur, 2015, 9 (3): 140- 156.
|
| 48 |
VAN SCHYNDEL R G,TIRKEL A Z,OSBORNE C F. A digital watermark[C] //Proceedings of 1st International Conference on Image Processing,1994,2:86-90.
|
| 49 |
ZEKI A M, MANAF A A. A novel digital watermarking technique based on ISB (Intermediate Significant Bit)[J]. World Academy of Science, Engineering and Technology, 2009, 50, 989- 996.
|
| 50 |
TIRKEL A Z,OSBORNE C F,VAN SCHYNDEL R G. Image watermarking-a spread spectrum application[C]//Proceedings of ISSSTA’95 International Symposium on Spread Spectrum Techniques and Applications,1996:785-789.
|
| 51 |
CHOI Y,AIZAWA I. Digital watermarking using inter-block correlation [C]//Proceedings 1999 International Conference on Image Processing (Cat. 99CH36348),1999:216-220.
|
| 52 |
CELIK M U,SHARMA G,SABER E,et al. Hierarchical watermarking for secure image authentication with localization[J]. IEEE Transactions on Image Processing,2002,11(6):585-595.
|
| 53 |
BENDER W, GRUHL D, MORIMOTO N, et al. Techniques for data hiding[J]. IBM Systems Journal, 1996, 35 (3/4): 313- 336.
|
| 54 |
COX I J,KILIAN J,LEIGHTON F T,et al. Secure spread spectrum watermarking for multimedia[J]. IEEE Transactions on Image Processing,1997,6(12):1673-1687.
|
| 55 |
WANG Y L,PEARMAIN A. Blind MPEG-2 video watermarking robust against geometric attacks:A set of approaches in DCT domain[J].IEEE Transactions on Image Processing,2006,15(6):1536-1543.
|
| 56 |
LIU R,TAN T. An SVD-based watermarking scheme for protecting rightful ownership [J].IEEE Transactions on Multimedia,2002,4(1):121-128.
|
| 57 |
HUAN W, LI S, QIAN Z, et al. Exploring stable coefficients on joint sub-bands for robust video watermarking in DT CWT domain[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2021, 32 (4): 1955- 1965.
|
| 58 |
BISWAS S,DAS S R,PETRIU E M. An adaptive compressed MPEG-2 video watermarking scheme[J]. IEEE Transactions on Instrumentation and Measurement,2005,54(5):1853-1861.
|
| 59 |
NOORKAMI M,MERSEREAU R M. A framework for robust watermarking of H. 264-encoded video with controllable detection performance[J]. IEEE Transactions on Information Forensics and Security,2007,2(1):14-23.
|
| 60 |
GAJ S, KANETKAR A, SUR A, et al. Drift-compensated robust watermarking algorithm for H. 265/HEVC video stream[J]. ACM Transactions on Multimedia Computing, Communications, and Applications (TOMM), 2017, 13 (1): 1- 24.
|
| 61 |
MAXEMCHUK N F,LOW S H. Marking text documents[C]//Proceedings 1997 International Conference on Image Processing,ICIP ’97,Santa Barbara,California,USA,IEEE Computer Society,1997:13.
|
| 62 |
BRASSIL J T,LOW S,MAXEMCHUK N F. Copyright protection for the electronic distribution of text documents[C]. Proceedings of the IEEE,1999,87(7):1181-1196.
|
| 63 |
ATALLAH M J,RASKIN V,HEMPELMANN C F,et al. Natural language watermarking and tamper proofing[C]//International Workshop on Information Hiding,2002:196-212.
|
| 64 |
HUA G,HUANG J,SHI Y Q,et al. Twenty years of digital audio watermarking—a comprehensive review[J]. Signal Processing,2016,128:222-242.
|
| 65 |
HU D, ZHAO D, ZHENG S. A new robust approach for reversible database watermarking with distortion control[J]. IEEE Transactions on Knowledge and Data Engineering, 2018, 31 (6): 1024- 1037.
|
| 66 |
ZHU J,KAPLAN R,JOHNSON J,et al. Hidden:Hiding data with deep networks [C]//Proceedings of the European Conference on Computer Vision (ECCV),2018:657-672.
|
| 67 |
AHMADI M,NOROUZI A,KARIMI N,et al. ReDMark:framework for residual diffusion watermarking based on deep networks[J]. Expert Systems with Applications,2020,146:113157.
|
| 68 |
TANCIK M,MILDENHALL B,NG R. Stegastamp:Invisible hyperlinks in physical photographs[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2020:2117-2126.
|
| 69 |
LIU Y,GUO M,ZHANG J,et al. A novel two-stage separable deep learning framework for practical blind watermarking[C]//Proceedings of the 27th ACM International Conference on Multimedia,2019:1509-1517.
|
| 70 |
LUO X,ZHAN R,CHANG H,et al. Distortion agnostic deep watermarking[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2020:13548-13557.
|
| 71 |
JIA Z,FANG H,ZHANG W. Mbrs:Enhancing robustness of DNN-based watermarking by mini-batch of real and simulated jpeg compression[C]//Proceedings of the 29th ACM International Conference on Multimedia,2021:41-49.
|
| 72 |
LIU G,SI Y,QIAN Z,et al. WRAP:watermarking approach robust against film-coating upon printed photographs[C]//Proceedings of the 31st ACM International Conference on Multimedia,2023:7274-7282.
|
| 73 |
FANG H,CHEN K,QIU Y,et al. DeNoL:A few-shot-sample-based decoupling noise layer for cross-channel watermarking robustness[C]//Proceedings of the 31st ACM International Conference on Multimedia,2023:7345-7353.
|
| 74 |
KENTON J D M W C,TOUTANOVA L K. Bert:Pre-training of deep bidirectional transformers for language understanding[C]//Proceedings of naacL-HLT, 2019:2.
|
| 75 |
YANG X,ZHANG J,CHEN K,et al. Tracing text provenance via context-aware lexical substitution[C]//Proceedings of the AAAI Conference on Artificial Intelligence,2022:11613-11621.
|
| 76 |
QIANG J,ZHU S,LI Y,et al. Natural language watermarking via paraphraser-based lexical substitution[J]. Artificial Intelligence,2023,317:103859.
|
| 77 |
ABDELNABI S,FRITZ M. Adversarial watermarking transformer:Towards tracing text provenance with data hiding[C]//2021 IEEE Symposium on Security and Privacy (SP),2021:121-140.
|
| 78 |
UCHIDA Y,NAGAI Y,SAKAZAWA S,et al. Embedding watermarks into deep neural networks[C]//Proceedings of the 2017 ACM on International Conference on Multimedia Retrieval,2017:269-277.
|
| 79 |
DARVISH R B,CHEN H,KOUSHANFAR F. Deepsigns:An end-toend watermarking framework for ownership protection of deep neural networks[C] //Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems,2019:485-497.
|
| 80 |
WANG T,KERSCHBAUM F. RIGA:Covert and robust white-box watermarking of deep neural networks[C]//Proceedings of the Web Conference,2021:9931004.
|
| 81 |
ZENG Y,TAN J,YOU Z,et al. Watermarks for generative adversarial network based on steganographic invisible backdoor[C]//2023 IEEE International Conference on Multimedia and Expo (ICME),2023:1211-1216.
|
| 82 |
JIA H,CHOQUETTE-CHOO C A,CHANDRASEKARAN V,et al. Entangled watermarks as a defense against model extraction[C]//30th USENIX Security Symposium (USENIX Security 21),2021:1937-1954.
|
| 83 |
OLIYNYK D,MAYER R,RAUBER A. I know what you trained last summer:A survey on stealing machine learning models and defenses[J]. ACM Computing Surveys,2023,55:1-41.
|
| 84 |
LI Y,JIANG Y,LI Z,et al. Backdoor learning:A survey[J]. IEEE Transactions on Neural Networks and Learning Systems,2022,1:5-22.
|
| 85 |
ZHANG J,GU Z,JANG J,et al. Protecting intellectual property of deep neural networks with watermarking[C]//Proceedings of the 2018 on Asia Conference on Computer and Communications Security,2018:159-172.
|
| 86 |
ADI Y,BAUM C,CISSE M,et al. Turning your weakness into a strength:Watermarking deep neural networks by backdooring[C]//27th USENIX Security Symposium (USENIX Security 18),2018:1615-1631.
|
| 87 |
QUAN Y, TENG H, CHEN Y, et al. Watermarking deep neural networks in image processing[J]. IEEE Transactions on Neural Networks and Learning Systems, 2020, 32 (5): 1852- 1865.
|
| 88 |
LI H, WENGER E, SHAN S, et al. Piracy resistant watermarks for deep neural networks[J]. arXiv preprint arXiv:, 1910, 01226, 2019.
|
| 89 |
GUO J,POTKONJAK M. Watermarking deep neural networks for embedded systems[C]//2018 IEEE/ACM International Conference on Computer-Aided Design (ICCAD). IEEE,2018:1-8.
|
| 90 |
ZHU R,ZHANG X,SHI M,et al. Secure neural network watermarking protocol against forging attack[J]. EURASIP Journal on Image and Video Processing,2020:1-12.
|
| 91 |
LE MERRER E,PEREZ P,TRÉDAN G. Adversarial frontier stitching for remote neural network watermarking[J]. Neural Computing and Applications,2020,32:9233-9244.
|
| 92 |
LI Z,HU C,ZHANG Y,et al. How to prove your model belongs to you:A blind-watermark based framework to protect intellectual property of DNN[C]//Proceedings of the 35th Annual Computer Security Applications Conference,2019:126-137.
|
| 93 |
NAMBA R,SAKUMA J. Robust watermarking of neural network with exponential weighting[C]//Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security,2019:228-240.
|
| 94 |
ZHONG Q,ZHANG L Y,ZHANG J,et al. Protecting IP of deep neural networks with watermarking:A new label helps[C]//Advances in Knowledge Discovery and Data Mining:24th Pacific-Asia Conference,PAKDD 2020,Singapore. Springer International Publishing,2020:462-474.
|
| 95 |
ZHANG Y Q,JIA Y R,WANG X,et al. DeepTrigger:a watermarking scheme of deep learning models based on chaotic automatic data annotation[J]. IEEE Access,2020,8:213296-213305.
|
| 96 |
CHEN H, ROUHANI B D, KOUSHANFAR F. Blackmarks: Blackbox multibit watermarking for deep neural networks[J]. [EB]. arXiv preprint arXiv:, 1904, 00344, 2019.
|
| 97 |
XU X R, LI Y Q, YUAN C. A novel method for identifying the deep neural network model with the serial number[J]. arXiv preprint arXiv:, 1911, 08053, 2019.
|
| 98 |
LI P,CHENG P,LI F,et al. Plmmark:a secure and robust black-box watermarking framework for pre-trained language models[C]//Proceedings of the AAAI Conference on Artificial Intelligence,2023:14991-14999.
|
| 99 |
PENG W, YI J, WU F, et al. Are you copying my model? protecting the copyright of large language models for eaas via backdoor watermark[J]. arXiv preprint arXiv:, 2305, 10036, 2023.
|
| 100 |
ZHAO Y, PANG T, DU C, et al. A recipe for watermarking diffusion models[J]. arXiv preprint arXiv:, 2303, 10137, 2023.
|
| 101 |
PENG S, CHEN Y, WANG C, et al. Protecting the intellectual property of diffusion models by the watermark diffusion process[J]. arXiv preprint arXiv:, 2306, 03436, 2023.
|
| 102 |
DEVLIN J, CHANG M W, LEE K, et al. Bert: Pre-training of deep bidirectional transformers for language understanding[J]. arXiv preprint arXiv:, 1810, 04805, 2018.
|
| 103 |
LIU Y, OTT M, GOYAL N, et al. Roberta: A robustly optimized bert pretraining approach[J]. arXiv preprint arXiv:, 1907, 11692, 2019.
|
| 104 |
YANG X,CHEN K,ZHANG W,et al. Watermarking text generated by blackbox language models[EB]. arXiv preprint arXiv:2305. 08883,2023.
|
| 105 |
YOO K,AHN W,JANG J,et al. Robust multi-bit natural language watermarking through invariant features[EB]. arXiv preprint arXiv:2305. 01904,2023.
|
| 106 |
AL-HAJ A. Combined DWT-DCT digital image watermarking[J]. Journal of Computer Science,2007,3(9):740-746.
|
| 107 |
HE Y,HU Y. A proposed digital image watermarking based on DWT-DCT-SVD [C]//2018 2nd IEEE Advanced Information Management,Communicates,Electronic and Automation Control Conference (IMCEC),2018:1214-1218.
|
| 108 |
ZHANG K A, XU L, CUESTA-INFANTE A, et al. Robust invisible video watermarking with attention[J]. [EB]. arXiv preprint arXiv:, 1909, 01285, 2019.
|
| 109 |
JIANG Z, ZHANG J, GONG N Z. Evading watermark based detection of AI-generated content[J]. arXiv preprint arXiv:, 2305, 03807, 2023.
|
| 110 |
TOUVRON H, LAVRIL T, IZACARD G, et al. Llama: Open and efficient foundation language models[J]. arXiv preprint arXiv:, 2302, 13971, 2023.
|
| 111 |
KIRCHENBAUER J, GEIPING J, WEN Y, et al. A watermark for large language models[J]. [EB]. arXiv preprint arXiv:, 2301, 10226, 2023.
|
| 112 |
KIRCHENBAUER J, GEIPING J, WEN Y, et al. On the reliability of watermarks for large language models[J]. arXiv preprint arXiv:, 2306, 04634, 2023.
|
| 113 |
CHRIST M, GUNN S, ZAMIR O. Undetectable watermarks for language models[J]. arXiv preprint arXiv:, 2306, 09194, 2023.
|
| 114 |
KUDITIPUDI R, THICKSTUN J, HASHIMOTO T, et al. Robust distortion-free watermarks for language models[J]. arXiv preprint arXiv:, 2307, 15593, 2023.
|
| 115 |
FU Y, XIONG D, DONG Y. Watermarking conditional text generation for ai detection: Unveiling challenges and a semantic-aware watermark remedy[J]. arXiv preprint arXiv:, 2307, 13808, 2023.
|
| 116 |
ZHANG R, HUSSAIN S S, NEEKHARA P, et al. REMARK-LLM: A robust and efficient watermarking framework for generative large language models[J]. arXiv preprint arXiv:, 2310, 12362, 2023.
|
| 117 |
LIU A, PAN L, HU X, et al. A semantic invariant robust watermark for large language models[J]. arXiv preprint arXiv:, 2310, 06356, 2023.
|
| 118 |
HOU A B, ZHANG J, HE T, et al. Semstamp: A semantic watermark with paraphrastic robustness for text generation[J]. arXiv preprint arXiv:, 2310, 03991, 2023.
|
| 119 |
WU Y, HU Z, ZHANG H, et al. DiPmARK: A stealthy, efficient and resilient watermark for large language models[J]. [EB]. arXiv preprint arXiv:, 2310, 07710, 2023.
|
| 120 |
MUNYER T, ZHONG X. Deeptextmark: Deep learning based text watermarking for detection of large language model generated text[J]. arXiv preprint arXiv:, 2305, 05773, 2023.
|
| 121 |
YOO K, AHN W, KWAK N. Advancing beyond identification: multi-bit watermark for language models[J]. arXiv preprint arXiv:, 2308, 00221, 2023.
|
| 122 |
FERNANDEZ P, CHAFFIN A, TIT K, et al. Three bricks to consolidate watermarks for large language models[J]. arXiv preprint arXiv:, 2308, 00113, 2023.
|
| 123 |
WANG L, YANG W, CHEN D, et al. Towards codable text watermarking for large language models[J]. arXiv preprint arXiv:, 2307, 15992, 2023.
|
| 124 |
ROMBACH R,BLATTMANN A,LORENZ D,et al. High-resolution image synthesis with latent diffusion models[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2022:10684-10695.
|
| 125 |
BETKER J,GOH G,JING L,et al. Improving image generation with better captions[EB]. Computer Science,2023.
|
| 126 |
YU L, SHI B, PASUNURU R, et al. Scaling autoregressive multi-modal models: Pretraining and instruction tuning[J]. arXiv preprint arXiv:, 2309, 02591, 2023.
|
| 127 |
FERNANDEZ P, COUAIRON G, JÉGOU H, et al. The stable signature: Rooting watermarks in latent diffusion models[J]. arXiv preprint arXiv:, 2303, 15435, 2023.
|
| 128 |
FENG W, HE J, ZHANG J, et al. Catch you everything everywhere: Guarding textual inversion via concept watermarking[J]. arXiv preprint arXiv:, 2309, 05940, 2023.
|
| 129 |
LIU Y, LI Z, BACKES M, et al. Watermarking diffusion model[J]. arXiv preprint arXiv:, 2305, 12502, 2023.
|
| 130 |
CUI Y, REN J, XU H, et al. Diffusionshield: A watermark for copyright protection against generative diffusion models[J]. arXiv preprint arXiv:, 2306, 04642, 2023.
|
| 131 |
WEN Y, KIRCHENBAUER J, GEIPING J, et al. Tree-ring watermarks: fingerprints for diffusion images that are invisible and robust[J]. [EB]. arXiv preprint arXiv:, 2305, 20030, 2023.
|
| 132 |
LI G, CHEN Y, ZHANG J, et al. Towards the vulnerability of watermarking artificial intelligence generated content[J]. arXiv preprint arXiv:, 2310, 07726, 2023.
|
| 133 |
BUI T,AGARWAL S,YU N,et al. RoSteALS:robust steganography using autoencoder latent space[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2023:933-942.
|
| 134 |
XIONG C,QIN C,FENG G,et al. Flexible and secure watermarking for latent diffusion model[C]//Proceedings of the 31st ACM International Conference on Multimedia,2023:1668-1676.
|
| 135 |
WEI P,LI S,ZHANG X,et al. Generative steganography network[C]// Proceedings of the 30th ACM International Conference on Multimedia,2022:1621-1629.
|
| 136 |
ZENG Y,TAN J,YOU Z,et al. Watermarks for generative adversarial network based on steganographic invisible backdoor[C]//2023 IEEE International Conference on Multimedia and Expo (ICME). IEEE,2023.
|
| 137 |
CHEN K,ZENG X,YING Q,et al. Invertible image dataset protection[C]//2022 IEEE International Conference on Multimedia and Expo (ICME),2022:01-06.
|
| 138 |
SALMAN H, KHADDAJ A, LECLERC G, et al. Raising the cost of malicious ai-powered image editing[J]. arXiv preprint arXiv:, 2302, 06588, 2023.
|
| 139 |
SHAN S, CRYAN J, WENGER E, et al. Glaze: Protecting artists from style mimicry by text-to-image models[J]. arXiv preprint arXiv:, 2302, 04222, 2023.
|
| 140 |
LI Y,ZHU M,YANG X,et al. Black-box dataset ownership verification via backdoor watermarking[J]. IEEE Transactions on Information Forensics and Security,2023,18:2318-2332.
|
| 141 |
LI Y, BAI Y, JIANG Y, et al. Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection[J]. Advances in Neural Information Processing Systems 35, 2022, 13238- 13250.
|
| 142 |
TANG R, FENG Q, LIU N, et al. Did you train on my dataset? towards public dataset protection with clean-label backdoor watermarking[J]. arXiv preprint arXiv:, 2303, 11470, 2023.
|
| 143 |
DITRIA L, DRUMMOND T. Hey that’s mine imperceptible watermarks are preserved in diffusion generated outputs[J]. arXiv preprint arXiv:, 2308, 11123, 2023.
|
| 144 |
LUO G, HUANG J, ZHANG M, et al. Steal my artworks for fine-tuning? a watermarking framework for detecting art theft mimicry in text-to-image models[J]. arXiv preprint arXiv:, 2311, 13619, 2023.
|
| 145 |
YAO H, LOU J, REN K, et al. Promptcare: Prompt copyright protection by watermark injection and verification[J]. arXiv preprint arXiv:, 2308, 02816, 2023.
|
| 146 |
ZHANG X,KARAMAN S,CHANG S F. Detecting and simulating artifacts in GAN fake images[C]//2019 IEEE International Workshop on Information Forensics and Security (WIFS),2019:1-6.
|
| 147 |
WANG S Y,WANG O,ZHANG R,et al. CNN-generated images are surprisingly easy to spot… for now[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2020:8695-8704.
|
| 148 |
LIU B,YANG F,BI X,et al. Detecting generated images by real images[C]// European Conference on Computer Vision,2022:95-110.
|
| 149 |
JU Y,JIA S,KE L,et al. Fusing global and local features for generalized aisynthesized image detection[C]//2022 IEEE International Conference on Image Processing (ICIP),2022:3465-3469.
|
| 150 |
TAN C,ZHAO Y,WEI S,et al. Learning on gradients:generalized artifacts representation for GAN-generated images detection[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2023:12105-12114.
|
| 151 |
OJHA U,LI Y,LEE Y J. Towards universal fake image detectors that generalize across generative models[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2023:24480-24489.
|
| 152 |
WANG Z,BAO J,ZHOU W,et al. DIRE for diffusion-generated image detection [C]//Proceedings of the IEEE/CVF international Conference on Computer Vision,2023:22445-22455.
|
| 153 |
ROSSLER A,COZZOLINO D,VERDOLIVA L,et al. Faceforensics++:Learning to detect manipulated facial images[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2019:1-11.
|
| 154 |
LIU Z,QI X,TORR P H. Global texture enhancement for fake face detection in the wild[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2020:8060-8069.
|
| 155 |
FRANK J,EISENHOFER T,SCHÖNHERR L,et al. Leveraging frequency analysis for deep fake image recognition[C]//International Conference on Machine Learning,2020:3247-3258.
|
| 156 |
ZHU M, CHEN H, YAN Q, et al. GenImage: A million-scale benchmark for detecting AI-generated image[J]. arXiv preprint arXiv:, 2306, 08571, 2023.
|
| 157 |
ZHONG N, XU Y, QIAN Z, et al. Rich and poor texture contrast: a simple yet effective approach for AI-generated image detection[J]. arXiv preprint arXiv:, 2311, 12397, 2023.
|
| 158 |
WU J, YANG S, ZHAN R, et al. A survey on LLM-gernerated text detection: necessity, methods, and future directions[J]. arXiv preprint arXiv:, 2310, 14724, 2023.
|
| 159 |
YU N,DAVIS L S,FRITZ M. Attributing fake images to GANs:learning and analyzing GAN fingerprints[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2019:7556-7566.
|
| 160 |
GIRISH S,SURI S,RAMBHATLA S S,et al. Towards discovery and attribution of open-worldGAN generated images[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2021:14094-14103.
|
| 161 |
BUI T,YU N,COLLOMOSSE J. Repmix:representation mixing for robust attribution of synthesized images[C]//European Conference on Computer Vision,2022:146-163.
|
| 162 |
HIROFUMI S,FUKUCHI K,AKIMOTO Y,et al. Did you use my GAN to generate fake? post-hoc attribution of GAN generated images via latent recovery [C]//2022 International Joint Conference on Neural Networks (IJCNN),2022:1-8.
|
| 163 |
YANG T,WANG D,TANG F,et al. Progressive open space expansion for open-set model attribution[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2023:15856-15865.
|
| 164 |
SHA Z,LI Z,YU N,et al. De-fake:detection and attribution of fake images generated by text-to-image generation models[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security,2023:3418-3432.
|
| 165 |
FERNANDES S,RAJ S,EWETZ R,et al. Detecting deepfake videos using attribution-based confidence metric[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops,2020:308-309.
|
| 166 |
YANG T,HUANG Z,CAO J,et al. Deepfake network architecture attribution[C] //Proceedings of the AAAI Conference on Artificial Intelligence,2022:4662-4670.
|
| 167 |
JIA S,LI X,LYU S. Model attribution of face-swap deepfake videos[C]//2022 IEEE International Conference on Image Processing (ICIP),2022:2356-2360.
|
| 168 |
SUN Z,CHEN S,YAO T,et al. Contrastive pseudo learning for open-world deepfake attribution[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2023:20882-20892.
|
| 169 |
JAWAHAR G,ABDUL-MAGEED M,LAKS LAKSHMANAN V. Automatic detection of machine generated text:a critical survey[C]//Proceedings of the 28th International Conference on Computational Linguistics,2020:2296-2309.
|
| 170 |
UCHENDU A,LE T,LEE D. Attribution and obfuscation of neural text authorship:A data mining perspective[J]. ACM SIGKDD Explorations Newsletter,2023,25(1):1-18.
|
| 171 |
UCHENDU A,LE T,SHU K,et al. Authorship attribution for neural text generation[C]//Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP),2020:8384-8395.
|
| 172 |
JONES K,NURSE J R,LI S. Are you robert or roberta? deceiving online authorship attribution models using neural text generators[C]//Proceedings of the International AAAI Conference on Web and Social Media,2022:429-440.
|
| 173 |
MUNIR S,BATOOL B,SHAFIQ Z,et al. Through the looking glass:Learning to attribute synthetic text generated by language models[C]//Proceedings of the 16th Conference of the European Chapter of the Association for Computational Linguistics:Main Volume,2021:1811-1822.
|
| 174 |
ABBURI H,SUESSERMAN M,PUDOTA N,et al. An ensemble-based approach for generative language model attribution[C]//International Conference on Web Information Systems Engineering,2023:699-709.
|
| 175 |
LI L, WANG P, REN K, et al. Origin tracing and detecting of LLMs[J]. [EB]. arXiv preprint arXiv:, 2304, 14072, 2023.
|
| 176 |
KUMARAGE T, LIU H. Neural authorship attribution: Stylometric analysis on large language models[J]. arXiv preprint arXiv:, 2308, 07305, 2023.
|
| 177 |
VENKATRAMAN S, UCHENDU A, LEE D. Gpt-who: an information densitybased machine-generated text detector[J]. arXiv preprint arXiv:, 2310, 06202, 2023.
|
| 178 |
WU K, PANG L, SHEN H, et al. LLMDet: a large language models detection tool[J]. arXiv preprint arXiv:, 2305, 15004, 2023.
|
| 179 |
YANG X, CHENG W, PETZOLD L, et al. DNA-GPT: divergent n-gram analysis for training-free detection of GPT-generated text[J]. arXiv preprint arXiv:, 2305, 17359, 2023.
|
/
| 〈 |
|
〉 |