Recent text-to-image diffusion models have shown surprising performance in generating high-quality images. However, concerns have arisen regarding the unauthorized usage of data during the training process. One example is when a model trainer collects a set of images created by a particular artist and attempts to train a model capable of generating similar images without obtaining permission from the artist. To address this issue, it becomes crucial to detect unauthorized data usage. In this paper, we propose a method for detecting such unauthorized data usage by planting injected memorization into the text-to-image diffusion models trained on the protected dataset. Specifically, we modify the protected image dataset by adding unique contents on the images such as stealthy image wrapping functions that are imperceptible to human vision but can be captured and memorized by diffusion models. By analyzing whether the model has memorization for the injected content (i.e., whether the generated images are processed by the chosen post-processing function), we can detect models that had illegally utilized the unauthorized data. Our experiments conducted on Stable Diffusion and LoRA model demonstrate the effectiveness of the proposed method in detecting unauthorized data usages.
翻译:近期,文本到图像扩散模型在生成高质量图像方面展现出令人惊叹的性能。然而,训练过程中未授权使用数据的问题引发了关注。例如,模型训练者收集某位艺术家创作的图像集,试图训练出一个能够生成相似图像的模型,而未获得艺术家的许可。为解决这一问题,检测未授权数据使用变得至关重要。本文提出了一种检测此类未授权数据使用的方法,通过在受保护数据集上训练的文本到图像扩散模型中植入注入记忆来实现。具体而言,我们修改受保护图像数据集,在图像上添加独特内容,例如人眼难以察觉但扩散模型能够捕获并记忆的隐蔽图像包裹函数。通过分析模型是否对注入内容存在记忆(即生成图像是否经过所选后处理函数处理),我们可以检测出非法使用了未授权数据的模型。我们在Stable Diffusion和LoRA模型上进行的实验表明,所提方法在检测未授权数据使用方面具有有效性。