Low-Rank Adaptation (LoRA) has become a widely used mechanism for customizing text-to-image diffusion models, enabling lightweight modules that are shared, reused, and commercialized as independent assets. This LoRA-centric ecosystem shifts copyright protection from foundation models to distributed LoRA modules, which are easy to copy, redistribute, or reuse without authorization. Existing watermarking methods either protect the base diffusion model or require watermark-aware retraining for each target LoRA, limiting their practicality in open community settings. To address this limitation, we propose LoRA-Key, a user-centric LoRA watermarking framework that treats copyright protection as a reusable ownership key. LoRA-Key encapsulates a recoverable secret message into a standalone user-specific Watermark LoRA, which can be attached to different target LoRAs through training-free linear superposition without per-LoRA retraining or structural modification. To train such a reusable key, we first establish a latent watermark prior in the frozen VAE latent space for robust message embedding and recovery, and then optimize the Watermark LoRA with message-conditioned watermark supervision and semantic consistency constraints. We further introduce Gradient Orthogonal Projection (GOP) to suppress watermark updates that conflict with semantic-preserving directions, reducing interference with generation fidelity and downstream style adaptation. Extensive experiments show that LoRA-Key provides lightweight plug-and-play copyright protection while preserving generation quality and style fidelity, and maintains robust ownership verification under image-level distortions, downstream fine-tuning, and multi-LoRA composition.
翻译:低秩适配(Low-Rank Adaptation, LoRA)已成为定制文本到图像扩散模型的广泛使用机制,它使得轻量级模块可以作为独立资产被共享、复用和商业化。这种以LoRA为核心的生态系统将版权保护从基础模型转向易被未经授权复制、再分发或复用的分布式LoRA模块。现有水印方法要么保护基础扩散模型,要么需要对每个目标LoRA进行水印感知重训练,这在开放社区场景中限制了其实用性。为解决这一局限,我们提出LoRA-Key,一种将版权保护视为可复用所有权密钥的面向用户LoRA水印框架。LoRA-Key将可恢复的秘密信息封装到独立的用户特定水印LoRA(Watermark LoRA)中,该水印LoRA可通过无训练的线性叠加附加到不同目标LoRA上,无需对每个LoRA进行重训练或结构调整。为训练这种可复用密钥,我们首先在冻结的VAE潜空间建立潜在水印先验以实现鲁棒的消息嵌入与恢复,随后通过消息条件水印监督和语义一致性约束优化水印LoRA。我们进一步提出梯度正交投影(Gradient Orthogonal Projection, GOP)来抑制与语义保持方向冲突的水印更新,减少对生成保真度和下游风格适配的干扰。大量实验表明,LoRA-Key在保持生成质量和风格保真度的同时,提供了轻量级即插即用版权保护,并在图像级失真、下游微调及多LoRA组合场景下维持了稳健的所有权验证。