跳到正文
arXiv:cs.LG· Cheng-Han Yeh, Kuan-chun Yu, Cheng-Chang Tsai, Chun-Shien Lu·· 4 小时前AI 评分45

基于潜空间的水印方法为何天生鲁棒性有限:扩散模型水印的理论分析

On the Intrinsic Limited Robustness of Latent-Based Watermarking

AI 导读

研究首次从理论上分析了基于潜空间的水印方法为何对旋转、缩放、平移(RST)等图像扰动缺乏不变性,并推导出刻画像素空间扰动与潜空间效应关系的最大扰动界。作者同时给出首个覆盖实际检测机制各环节的解析公式,并通过实验验证了现有范式下这类水印方法的内在鲁棒性局限。研究最后提供了分析工具与设计指南供后续研究参考。

正文

View PDF HTML (experimental)

Abstract:Existing latent-based watermarking methods for diffusion models have overestimated their robustness to image distortions, including geometric transformations such as rotation, scaling, and translation (RST). Moreover, this paradigm of watermarking approaches may suffer from inherent limitations arising from the domain in which the watermark is embedded. In this paper, we provide the first theoretical analysis explaining why these methods lack invariance to perturbations. By relaxing the invariant relation, we derive a maximum perturbation bound that characterizes the relationship between pixel-space perturbations and their corresponding effects in latent space. In addition, we present the first analytical formulation that captures all components of practical detection mechanisms. Finally, we conduct experiments to validate the theoretical findings and the limitations of latent-based watermarking methods. Our theoretical and empirical results indicate that, under the current design paradigm, latent-based watermarking methods intrinsically exhibit limited robustness. We conclude by providing the analytical tool and design guidelines that future research could follow.
Subjects: Machine Learning (cs.LG); Cryptography and Security (cs.CR)
Cite as: arXiv:2610.08178 [cs.LG]
  (or arXiv:2610.08178v1 [cs.LG] for this version)
  https://doi.org/10.48550/arXiv.2610.08178

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Cheng-Han Yeh [view email]
[v1] Tue, 6 Oct 2026 11:29:50 UTC (10,261 KB)

来源:arXiv:cs.LG · arxiv.org