Diffusion models have demonstrated remarkable capabilities across a range of tasks and have become the backbone of various web applications, such as text-to-image, image-to-image, and text-to-video generation. Obtaining large, high-performance diffusion models demands significant resources, highlighting their importance as Intellectual Property (IP) worth protecting. Watermarking is widely adopted as the mainstream technique for model IP protection. However, existing watermarking methods designed for discriminative models are insufficient for protection diffusion models. This paper introduces WDM, a novel watermarking solution for diffusion models without imprinting the watermark during task generation. It involves training a model to concurrently learn a Watermark Diffusion Process (WDP) for embedding watermarks alongside the standard diffusion process for task generation. We provide a detailed theoretical analysis of the training and sampling in WDP, relating it to a shifted Gaussian diffusion process via the same reverse noise. Watermarks are extracted using a designated trigger, ensuring they stay unexposed during the primary task sampling. We further present a complete framework for verifying copyright infringement through hypothesis testing. Extensive experiments have validated the effectiveness and robustness of our approach in various trigger and watermark data configurations.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Intellectual Property Protection of Diffusion Models via the Watermark Diffusion Process

  • Sen Peng,
  • Yufei Chen,
  • Cong Wang,
  • Xiaohua Jia

摘要

Diffusion models have demonstrated remarkable capabilities across a range of tasks and have become the backbone of various web applications, such as text-to-image, image-to-image, and text-to-video generation. Obtaining large, high-performance diffusion models demands significant resources, highlighting their importance as Intellectual Property (IP) worth protecting. Watermarking is widely adopted as the mainstream technique for model IP protection. However, existing watermarking methods designed for discriminative models are insufficient for protection diffusion models. This paper introduces WDM, a novel watermarking solution for diffusion models without imprinting the watermark during task generation. It involves training a model to concurrently learn a Watermark Diffusion Process (WDP) for embedding watermarks alongside the standard diffusion process for task generation. We provide a detailed theoretical analysis of the training and sampling in WDP, relating it to a shifted Gaussian diffusion process via the same reverse noise. Watermarks are extracted using a designated trigger, ensuring they stay unexposed during the primary task sampling. We further present a complete framework for verifying copyright infringement through hypothesis testing. Extensive experiments have validated the effectiveness and robustness of our approach in various trigger and watermark data configurations.