Nowadays, the family of Stable Diffusion (SD) models has gained prominence for its high quality outputs and scalability. This has also raised security concerns on social media, as malicious users can create and disseminate harmful content. Existing approaches involve training components or entire SDs to embed a watermark in generated images for traceability and responsibility attribution. However, in the era of AI-generated content (AIGC), the rapid iteration of SDs renders retraining with watermark models costly. To address this, we propose a training-free plug-and-play watermark framework for SDs. Without modifying any components of SDs, we embed diverse watermarks in the latent space, adapting to the denoising process. Our experimental findings reveal that our method effectively harmonizes image quality and watermark invisibility. Furthermore, it performs robustly under various attacks. We also have validated that our method is generalized to multiple versions of SDs, even without retraining the watermark model.
翻译:如今,Stable Diffusion(SD)模型系列因其高质量输出和可扩展性而备受关注。然而,这也引发了社交媒体上的安全隐患,恶意用户可借此创建并传播有害内容。现有方法通常通过训练SD的组件或完整模型,在生成图像中嵌入水印以实现溯源和责任归属。然而,在AI生成内容(AIGC)时代,SD模型的快速迭代使得基于水印模型的重新训练成本高昂。为此,我们提出一种免训练的即插即用水印框架。在不修改SD任何组件的前提下,我们在潜在空间中嵌入多样化水印,使其自适应去噪过程。实验结果表明,该方法能有效平衡图像质量与水印不可见性,并在多种攻击下表现稳健。此外,我们验证了该方法可泛化至多个SD版本,且无需重新训练水印模型。