Abstract
We revisit Tree-Ring Watermarking, a recent diffusion model watermarking method that demonstrates great robustness to various attacks. We conduct an in-depth study on it and reveal that the distribution shift unintentionally introduced by the watermarking process, apart from watermark pattern matching, contributes to its exceptional robustness. Our investigation further exposes inherent flaws in its original design, particularly in its ability to identify multiple distinct keys, where distribution shift offers no assistance. Based on these findings and analysis, we present RingID for enhanced multi-key identification. It consists of a novel multi-channel heterogeneous watermarking approach designed to seamlessly amalgamate distinctive advantages from diverse watermarks. Coupled with a series of suggested enhancements, RingID exhibits substantial advancements in multi-key identification.
Abstract (translated)
我们复习了Tree-Ring Watermarking,一种最近的多扩散模型水印方法,它表现出对各种攻击的极大鲁棒性。我们对它进行了深入的研究,并发现除了水印模式匹配之外,水印过程无意中引入的分布偏移对它的非凡鲁棒性做出了贡献。我们的调查进一步揭示了其原始设计固有的缺陷,特别是在其无法识别多个不同密钥的能力上。基于这些发现和分析,我们提出了RingID,用于增强多密钥识别。它是一种新型的多通道异质水印方法,旨在无缝结合各种水印的显著优势。与一系列建议的改进相结合,RingID在多密钥识别方面取得了显著的进步。
URL
https://arxiv.org/abs/2404.14055