Lune

USENIX Security2026顶会

Identifying Provenance of Generative Text-to-Image Models

Anna Yoo Jeong Ha, Wenxin Ding, Stanley Wu, Shawn Shan, Haitao Zheng, Ben Y. Zhao

出版方
2026年份

摘要

Fine-tuning provides a fast and cheap way to produce new text-to-image models that are often indistinguishable from ones trained from scratch. Unfortunately, misrepresentation of fine-tuned models creates problems for AI companies and users alike, by disincentivizing competition and misleading users on model quality and ethics of its training process.

In this paper, we propose a model provenance system that identifies models produced by fine-tuning on existing base text-to-image models, using only black-box query access to the models. Our design is informed by analysis showing that one can quantify the feature space difference between textto-image models by analyzing their responses to detailed prompts. Given a target model, our system analyzes its output, extracts visual features using a generic feature extractor, and compares the distribution against those derived from a pool of base models using Jensen-Shannon divergence. We then apply statistical hypothesis testing to determine if the target model is trained from scratch or fine-tuned, and if the latter, the likely base (parent) model. We evaluate our system across seven popular diffusion models and numerous fine-tuned variants. Our results show high accuracy in attributing model lineage, even under adversarial conditions such as image postprocessing or weight perturbations. Finally, we demonstrate real-world efficacy of our system by tracing provenance of in-the-wild models from popular online platforms.

Model trainer fine-tunes and claims ownership of the fine-tuned model.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper25

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖