Protecting deep neural networks (DNNs) against intellectual property (IP) infringement has attracted an increasing attention in recent years. Recent advances focus on IP protection of generative models, which embed the watermark information into the image generated by the model to be protected. Although the generated marked image has good visual quality, it introduces noticeable artifacts to the marked image in high-frequency area, which severely impairs the imperceptibility of the watermark and thereby reduces the security of the watermarking system. To deal with this problem, in this paper, we propose a novel framework for generative model watermarking that can suppress those high-frequency artifacts. The main idea of the proposed framework is to design a new watermark embedding network that can suppress high-frequency artifacts by applying anti-aliasing. To realize anti-aliasing, we use low-pass filtering for the internal sampling layers of the new watermark embedding network. Meanwhile, joint loss optimization and adversarial training are applied to enhance the effectiveness and robustness. Experimental results indicate that the marked model not only maintains the performance very well on the original task, but also demonstrates better imperceptibility and robustness on the watermarking task. This work reveals the importance of suppressing high-frequency artifacts for enhancing imperceptibility and security of generative model watermarking.
翻译:近年来,针对深度神经网络(DNNs)知识产权的侵权保护问题日益受到关注。最新研究聚焦于生成模型的知识产权保护,通过将被保护模型生成的图像嵌入水印信息来实现保护。虽然生成的带水印图像具有良好的视觉质量,但在高频区域会引入显著的伪影,严重损害水印的不可感知性,进而降低水印系统的安全性。为解决这一问题,本文提出了一种新型生成模型水印框架,能够有效抑制此类高频伪影。该框架的核心思想是通过抗混叠技术设计新型水印嵌入网络,从而抑制高频伪影。为实现抗混叠,我们在新型水印嵌入网络的内部采样层应用低通滤波,同时结合联合损失优化与对抗训练增强水印的有效性与鲁棒性。实验结果表明,带水印模型不仅能在原始任务中保持优异性能,在水印任务中更展现出更强的不可感知性与鲁棒性。本研究揭示了抑制高频伪影对提升生成模型水印不可感知性与安全性的重要意义。