生成图水印的前沿研究与展望
网络出版日期: 2024-05-18
基金资助
国家自然科学基金(62072250,62172435,U1804263,U20B2065,61872203,71802110,61802212);中原科技创新领军人才项目(214200510019);江苏省自然科学基金(BK20200750);河南省网络空间态势感知重点实验室开放基金(HNTS2022002);江苏省研究生研究与实践创新项目(KYCX200974);广东省信息安全技术重点实验室开放项目(2020B1212060078);山东省计算机网络重点实验室开放课题基金(SDKLCN-2022-05)
版权
Frontier research and prospect of watermarking for generated images
Online published: 2024-05-18
Copyright
随着人工智能生成内容(Artificial Intelligence Generated Content,AIGC)带来的深度合成浪潮,数字水印技术作为图像取证领域中的一种主动防御手段,被广泛应用于识别生成内容和模型的版权保护。因此,生成图水印越来越受到研究者的关注。首先,介绍了生成图水印的研究背景,从模型版权保护和AIGC监管两个角度介绍生成图水印的研究动机。接着,基于生成模型和水印技术的发展引出了生成图水印问题,将水印根据是否参与生成过程分为两类,并对这两类生成图水印的现状进行了详细的梳理和介绍。随后,对现有的生成图水印方法进行评估,在传统水印需满足的鲁棒性、不可察觉性和容量基础上,进一步提出了针对生成图水印的新要求。最后,指出生成图水印中有待进一步解决的问题及发展趋势。
王金伟 , 姜晓丽 , 谭贵峰 , 罗向阳 . 生成图水印的前沿研究与展望[J]. 网络空间安全科学学报, 2024 , 2(1) : 50 -62 . DOI: 10.20172/j.issn.2097-3136.240104
With the wave of deep synthesis brought about by AIGC (Artificial Intelligence Generative Content), digital watermarking technology was widely used to identify the copyright protection of generated content and models as an active defense method in the field of image forensics. Therefore, generating image watermarks had attracted more and more attention from researchers. Firstly, the research background of generative image watermarking was introduced, and the research motivation of generative image watermarking was introduced from the perspectives of model copyright protection and AIGC supervision. Then, based on the development of generation model and watermarking technology, the problem of generating image watermarks was introduced, and the watermarks were divided into two categories according to whether they participated in the generation process, and the current status of these two types of generated image watermarks was sorted out and introduced in detail. Subsequently, the existing methods of generating image watermarks were evaluated. On the basis of the robustness, imperceptibility and capacity of traditional watermarks, new requirements for generating image watermarks were further proposed. Finally, the problems and development trends that needed to be further solved in the generation of image watermarks were pointed out.
表 1 生成图水印评价Table 1 Evaluation of generate image watermark |
| 生成图水印 | 水印指标 | |||||||
| 类型 | 方法 | 容量 | 鲁棒性 | 不可感知性 | 生成质量 | |||
| 非恶意攻击 | 恶意攻击 | 图像 | 生成模型 | |||||
| 嵌入不参与生成过程 | 数据集 | Yu等[33] | n | √ | √ | × | √ | |
| Zhao等[35] | n | √ | √ | × | √ | |||
| Cui等[37] | n | √ | √ | √ | × | √ | ||
| 模型微调 | Ma等[40] | 0 | √ | √ | √ | × | √ | |
| Fernandez等[39] | n | √ | √ | √ | × | √ | ||
| 嵌入参与生成过程 | 深度学习算法结合生成过程 | Xiong等[41] | n | √ | √ | √ | × | √ |
| 数据分布 | Wen等[42] | 0 | √ | √ | √ | √ | ||
| Zhang等[44] | 0 | √ | √ | √ | √ | √ | ||
| Liu等[45] | 0 | √ | √ | √ | √ | |||
注:0代表零比特水印,n代表多比特水印,√代表考虑到相关特性,×代表未考虑到相关特性。 |
| 1 |
LIU Y,MA X,BAILEY J,et al. Reflection backdoor:A natural backdoor attack on deep neural networks[C]//Computer Vision–ECCV 2020:16th European Conference,Springer International Publishing,2020:182-199.
|
| 2 |
STEINHARDT J,KOH P W W,LIANG P S. Certified defenses for data poisoning attacks[J]. Advances in Neural Information Processing Systems 30,2017.
|
| 3 |
GUO J,POTKONUAK M. Watermarking deep neural networks for embedded systems[C]//2018 IEEE/ACM International Conference on Computer-Aided Design (ICCAD),IEEE,2018:1-8.
|
| 4 |
LI Z,HU C,ZHANG Y,et al. How to prove your model belongs to you:A blind-watermark based framework to protect intellectual property of DNN[C]//Proceedings of the 35th Annual Computer Security Applications Conference,2019:126-137.
|
| 5 |
CAO X,JIA J,GONG N Z. IPGuard:Protecting intellectual property of deep neural networks via fingerprinting the classification boundary[C]//Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security,2021:14-25.
|
| 6 |
GOODFELLOW I, POUGET-ABADIE J, MIRZA M, et al. Generative adversarial networks[J]. Communications of the ACM, 2020, 63 (11): 139- 144.
|
| 7 |
HO J, JAIN A, ABBEEL P. Denoising diffusion probabilistic models[J]. Advances in Neural Information Processing Systems, 2020, 33, 6840- 6851.
|
| 8 |
QUAN W, WANG K, YAN D M, et al. Distinguishing between natural and computer-generated images using convolutional neural networks[J]. IEEE Transactions on Information Forensics and Security, 2018, 13 (11): 2772- 2787.
|
| 9 |
WANG S Y,WANG O,ZHANG R,et al. CNN-generated images are surprisingly easy to spot.. for now[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2020:8695-8704.
|
| 10 |
QIAN Y,YIN G,SHENG L,et al. Thinking in frequency:face forgery detection by mining frequency-aware clues[C]//European Conference on Computer Vision,Cham:Springer International Publishing,2020:86-103.
|
| 11 |
FRANK J,EISENHOFER T,SCHÖNHERR L,et al. Leveraging frequency analysis for deep fake image recognition[C]//International Conference on Machine Learning,PMLR,2020:3247-3258.
|
| 12 |
ZHANG L,RAO A,AGRAWALA M. Adding conditional control to text-to-image diffusion models[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2023:3836-3847.
|
| 13 |
COX I, MILLER M, BLOOM J, et al. Digital watermarking[J]. Journal of Electronic Imaging, 2002, 11 (3): 414- 414.
|
| 14 |
POPESCU A C, FARID H. Exposing digital forgeries by detecting traces of resampling[J]. IEEE Transactions on Signal Processing, 2005, 53 (2): 758- 767.
|
| 15 |
BARNI M,BARTOLINI F. Watermarking systems engineering:Enabling digital assets security and other applications[M]. CRC Press,2004.
|
| 16 |
ASIKUZZAMAN M, PICKERING M R. An overview of digital video watermarking[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2017, 28 (9): 2131- 2153.
|
| 17 |
ZHANG X, WANG S, QIAN Z, et al. Reference sharing mechanism for watermark self-embedding[J]. IEEE Transactions on Image Processing, 2010, 20 (2): 485- 495.
|
| 18 |
吴汉舟, 张杰, 李越, 等. 人工智能模型水印研究进展[J]. 中国图象图形学报, 2023, 28 (6): 1792- 1810.
|
| 19 |
UCHIDA Y,NAGAI Y,SAKAZAWA S,et al. Embedding watermarks into deep neural networks[C]//Proceedings of the 2017 ACM on International Conference on Multimedia Retrieval,2017:269-277.
|
| 20 |
WANG J, WU H, ZHANG X, et al. Watermarking in deep neural networks via error back-propagation[J]. Electronic Imaging, 2020, 32, 1- 9.
|
| 21 |
WANG Y,YE J,WU H. Generating watermarked speech adversarial examples[C]//Proceedings of the ACM Turing Award Celebration Conference,China,2021:254-260.
|
| 22 |
WANG Y, WU H. Protecting the intellectual property of speaker recognition model by black-box watermarking in the frequency domain[J]. Symmetry, 2022, 14 (3): 619.
|
| 23 |
ZHANG T, WU H, LU X, et al. Awencoder: Adversarial watermarking pre-trained encoders in contrastive learning[J]. Applied Sciences, 2023, 13 (6): 3531.
|
| 24 |
TAN J,ZHONG N,QIAN Z,et al. Deep neural network watermarking against model extraction attack[C]//Proceedings of the 31st ACM International Conference on Multimedia,2023:1588-1597.
|
| 25 |
WU H, LIU G, YAO Y, et al. Watermarking neural networks with watermarked images[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2020, 31 (7): 2591- 2601.
|
| 26 |
ZHAO X,WU H,ZHANG X. Watermarking graph neural networks by random graphs[C]//2021 9th International Symposium on Digital Forensics and Security (ISDFS),IEEE,2021:1-6.
|
| 27 |
ZHANG L,LIU Y,LIU S,et al. Generative model watermarking based on human visual system[C]//International Forum on Digital TV and Wireless Multimedia Communications,2022:136-149.
|
| 28 |
ZHU J,KAPLAN R,JOHNSON J,et al. Hidden:Hiding data with deep networks[C]//Proceedings of the European Conference on Computer Vision (ECCV),2018:657-672.
|
| 29 |
JIA Z,FANG H,ZHANG W. Mbrs:Enhancing robustness of dnn-based watermarking by mini-batch of real and simulated jpeg compression[C]//Proceedings of the 29th ACM International Conference on Multimedia,2021:41-49.
|
| 30 |
VASWANI A,SHAZEER N,PARMAR N,et al. Attention is all you need[C]//Advances in Neural Information Processing Systems 30,2017.
|
| 31 |
KINGMA D P, WELLING M. Auto-encoding variational bayes[J]. arXiv preprint arXiv:, 1312, 6114, 2013.
|
| 32 |
ROMBACH R,BLATTMANN A,LORENZ D,et al. High-resolution image synthesis with latent diffusion models[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition,2022:10684-10695.
|
| 33 |
YU N,SKRIPNIUK V,ABDELNABI S,et al. Artificial fingerprinting for generative models:Rooting deepfake attribution in training data[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2021:14448-14457.
|
| 34 |
BALUJA S. Hiding images in plain sight:Deep steganography[C]//Advances in Neural Information Processing Systems 30,2017.
|
| 35 |
ZHAO Y,PANG T,DU C,et al. A recipe for watermarking diffusion models[EB]. arXiv preprint arXiv:2303,10137,2023.
|
| 36 |
KARRAS T, AITTALA M, AILA T, et al. Elucidating the design space of diffusion-based generative models[J]. Advances in Neural Information Processing Systems, 2022, 35, 26565- 26577.
|
| 37 |
CUI Y,REN J,LIN Y,et al. FT-Shield:a watermark against unauthorized fine-tuning in text-to-image diffusion models[EB]. arXiv preprint arXiv:2310. 02401,2023.
|
| 38 |
RONNEBERGER O,FISCHER P,BROX T. U-net:Convolutional networks for biomedical image segmentation[C]//Medical Image Computing and Computer-Assisted Intervention–MICCAI 2015:18th International Conference,Springer International Publishing,2015:234-241.
|
| 39 |
FERNANDEZ P,COUAIRON G,JÉGOU H,et al. The stable signature:Rooting watermarks in latent diffusion models[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision,2023:22466-22477.
|
| 40 |
MA Y,ZHAO Z,HE X,et al. Generative watermarking against unauthorized subject-driven image synthesis[EB]. arXiv preprint arXiv:2306. 07754,2023.
|
| 41 |
XIONG C,QIN C,FENG G,et al. Flexible and secure watermarking for latent diffusion model[C]//Proceedings of the 31st ACM International Conference on Multimedia,2023:1668-1676.
|
| 42 |
WEN Y,KIRCHENBAUER J,GEIPING J,et al. Tree-ring watermarks:Fingerprints for diffusion images that are invisible and robust[EB]. arXiv preprint arXiv:2305. 20030,2023.
|
| 43 |
SONG J, MENG C, ERMON S. Denoising diffusion implicit models[J]. arXiv preprint arXiv:, 2010, 02502, 2020.
|
| 44 |
ZHANG L, LIU X, MARTIN A V, et al. Robust image watermarking using stable diffusion[J]. arXiv preprint arXiv:, 2401, 04247, 2024.
|
| 45 |
LIU G H,CHEN T,THEODOROU E,et al. Mirror diffusion models for constrained and watermarked generation[C]//Advances in Neural Information Processing Systems 36,2024.
|
| 46 |
KIRCHENBAUER J, GEIPING J, WEN Y, et al. On the reliability of watermarks for large language models[J]. arXiv preprint arXiv:, 2306, 04634, 2023.
|
| 47 |
JIANG Z,ZHANG J,GONG N Z. Evading watermark based detection of AI-generated content[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security,2023:1168-1181.
|
| 48 |
CHEN J,JORDAN M I,WAINWRIGHT M J. Hopskipjumpattack:A query-efficient decision-based attack[C]//2020 IEEE Symposium on Security and Privacy (SP),IEEE,2020:1277-1294.
|
| 49 |
LI G, CHEN Y, ZHANG J, et al. Towards the vulnerability of watermarking artificial intelligence generated content[J]. arXiv preprint arXiv:, 2310, 07726, 2023.
|
| 50 |
ZHAO X, ZHANG K, WANG Y X, et al. Generative autoencoders as watermark attackers: Analyses of vulnerabilities and threats[J]. arXiv preprint arXiv:, 2306, 01953, 2023.
|
| 51 |
RADFORD A,KIM J W,HALLACY C,et al. Learning transferable visual models from natural language supervision[C]//International Conference on Machine Learning,PMLR,2021:8748-8763.
|
| 52 |
ZHANG H, EDELMAN B L, FRANCATI D, et al. Watermarks in the sand: Impossibility of strong watermarking for generative models[J]. arXiv preprint arXiv:, 2311, 04378, 2023.
|
| 53 |
SADASIVAN V S, KUMAR A, BALASUBRAMANIAN S, et al. Can AI-generated text be reliably detected?[J]. arXiv preprint arXiv:, 2303, 11156, 2023.
|
| 54 |
LIANG C, WU X. Mist: Towards improved adversarial examples for diffusion models[J]. arXiv preprint arXiv:, 2305, 12683, 2023.
|
| 55 |
YE X, HUANG H, AN J, et al. Duaw: Data-free universal adversarial watermark against stable diffusion customization[J]. arXiv preprint arXiv:, 2308, 09889, 2023.
|
| 56 |
张卫明, 陈可江, 俞能海. 可证安全隐写: 理论、应用与展望[J]. 网络空间安全科学学报, 2023, 1 (1): 38- 46.
ZHANG W M, CHEN K J, YU N H, et al. Provable secure steganography: Theory, application and prospects[J]. Journal of Cybersecurity, 2023, 1 (1): 38- 46.
|
/
| 〈 |
|
〉 |