Gaussian Shading: Provable Performance-Lossless Image Watermarking for Diffusion Models

Zijin Yang, Kai Zeng, Kejiang Chen, Han Fang, Wei Zhang, Neng H. Yu

arXiv:2404.04956 · 2026-07-27 공개 · arXiv · PDF

diffusion-models training-free latent-representations image-watermarking gaussian-shading performance-lossless ddim-inversion copyright-protection

Abstract

Ethical concerns surrounding copyright protection and inappropriate content generation pose challenges for the practical implementation of diffusion models. One effective solution involves watermarking the generated images. However, existing methods often compromise the model performance or require additional training, which is undesirable for operators and users. To address this issue, we propose Gaussian Shading, a diffusion model watermarking technique that is both performance-lossless and training-free, while serving the dual purpose of copyright protection and tracing of offending content. Our watermark embedding is free of model parameter modifications and thus is plug-and-play. We map the watermark to latent representations following a standard Gaussian distribution, which is indistinguishable from latent representations obtained from the non-watermarked diffusion model. Therefore we can achieve watermark embedding with lossless performance, for which we also provide theoretical proof Furthermore, since the watermark is intricately linked with image semantics, it exhibits resilience to lossy processing and erasure attempts. The watermark can be extracted by Denoising diffusion Implicit Models (DDIM) inversion and inverse sampling. We evaluate Gaussian Shading on multiple versions of Stable Diffusion, and the results demonstrate that Gaussian Shading not only is performance-lossless but also out-performs existing methods in terms of robustness.

한국어 요약

한 줄 요약

Gaussian Shading은 디퓨전 모델에 성능 저하 없이 훈련 없이 워터마킹을 적용하는 기법으로, 256비트 용량의 강력한 워터마킹을 달성한다.

핵심 기여도

핵심 아이디어

기존 워터마킹 방법은 모델 파라미터를 수정하거나 훈련 과정을 추가해야 하며, 이는 모델 성능 저하를 초래한다. 반면, Gaussian Shading은 **latent representation**에 워터마킹 정보를 삽입하는 방식으로, 이 정보는 **표준 가우시안 분포**를 따르며, 비워터마킹된 이미지의 latent와 구분되지 않는다. 이는 워터마킹이 모델의 생성 과정에 영향을 주지 않음을 의미하며, 성능 손실 없이 워터마킹을 가능하게 한다.

핵심적인 세 단계는 다음과 같다:
1. **Watermark Diffuse**: 워터마킹 정보를 latent 공간 전체에 확산시켜 이미지 의미와 밀접하게 연결.
2. **Randomization**: 워터마킹 정보를 무작위화하여 분포 일관성을 유지.
3. **Distribution-Preserving Sampling**: 워터마킹이 포함된 latent를 표준 가우시안 분포에 맞게 샘플링하여 성능 손실 방지.

기술적 접근법

주요 결과

의의 및 한계

Gaussian Shading은 **성능 손실 없이 워터마킹을 적용**할 수 있는 첫 번째 기법으로, 디퓨전 모델의 저작권 보호 및 부정 사용 추적에 중요한 기여를 한다. 특히, 모델 파라미터를 수정하지 않아 **플러그 앤 플레이 방식**으로 사용 가능하며, 기존 워터마킹 방법의 주요 단점을 극복한다.

하지만, 일부 노이즈 공격 (예: Random Crop, Gaussian Noise)에 대해 성능이 급격히 저하되는 한계가 있다. 또한, 워터마킹 용량은 256비트로 제한되어 더 많은 정보를 담는 데는 한계가 있다. 향후 연구에서는 **더 효율적인 inversion 방법**과 **다양한 샘플링 기법**을 포함한 확장이 필요하다.

실용적 활용

Gaussian Shading은 **AI 이미지 생성 플랫폼**, **디퓨전 모델 기반 콘텐츠 생성 업체**, **정부 및 기업의 AI 콘텐츠 감시 시스템** 등에서 활용 가능하다. 모델 제공자는 워터마킹을 추가하거나 제거할 수 있으며, 사용자 경험에는 영향을 주지 않아 실용성이 높다. 특히, **AI 생성 콘텐츠의 진위 판별 및 추적**에 유용하게 사용될 수 있다.