Single-Model Attribution of Generative Models Through Final-Layer Inversion
Mike Laszkiewicz, Jonas Ricker, Johannes Lederer, Asja Fischer
Abstract
Recent breakthroughs in generative modeling have sparked interest in practical single-model attribution. Such methods predict whether a sample was generated by a specific generator or not, for instance, to prove intellectual property theft. However, previous works are either limited to the closed-world setting or require undesirable changes to the generative model. We address these shortcomings by, first, viewing single-model attribution through the lens of anomaly detection. Arising from this change of perspective, we propose FLIPAD, a new approach for single-model attribution in the open-world setting based on final-layer inversion and anomaly detection. We show that the utilized final-layer inversion can be reduced to a convex lasso optimization problem, making our approach theoretically sound and computationally efficient. The theoretical findings are accompanied by an experimental study demonstrating the effectiveness of our approach and its flexibility to various domains.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- OmniMark: Efficient and Scalable Latent Diffusion Model FingerprintingJianwei Fei, Yunshu Dai, Zhihua Xia, Fangjun Huang et al.AAAI 2025 · 3 citations
- Tracing the Roots: Leveraging Temporal Dynamics in Diffusion Trajectories for Origin AttributionAndreas Floros, Seyed-Mohsen Moosavi-Dezfooli, Pier Luigi DragottiNeurIPS 2025 · 1 citation
- Untraceable DeepFakes via Traceable Fingerprint EliminationJiewei Lai, Lan Zhang, Chen Tang, Pengcheng Sun et al.ICLR 2026
- Where's the Liability in the Generative Era? Recovery-based Black-Box Detection of AI-Generated ContentHaoyue Bai, Yiyou Sun, Wei Cheng, Haifeng ChenCVPR 2025
Builds on18
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
- Alias-Free Generative Adversarial NetworksTero Karras, Miika Aittala, Samuli Laine, Erik Härkönen et al.NeurIPS 2021 · 2,126 citations
- Leveraging Frequency Analysis for Deep Fake Image RecognitionJoel Frank, Thorsten Eisenhofer, Lea Schönherr, Asja Fischer et al.ICML 2020 · 848 citations
Related papers
- Where Did I Come From? Origin Attribution of AI-Generated ImagesZhenting Wang, Chen Chen, Yi Zeng, Lingjuan Lyu et al.NeurIPS 2023 · 44 citations
- Attribution as Retrieval: Model-Agnostic AI-Generated Image AttributionHongsong Wang, Renxi Cheng, Chaolei Han, Jie GuiCVPR 2026 · 4 citations
- InvAD: Inversion-based Reconstruction-Free Anomaly Detection with Diffusion ModelsShunsuke Sakai, Xiangteng He, Chunzhi Gu, Leonid Sigal et al.CVPR 2026 · 3 citations
- Out-of-Distribution Detection with a Single Unconditional Diffusion ModelAlvin Heng, Alexandre H. Thiery, Harold SohNeurIPS 2024 · 35 citations
- Mechanistic Anomaly Detection via Functional AttributionHugo Lyons Keenan, Christopher Leckie, Sarah ErfaniICML 2026
