RoMa: A Robust Model Watermarking Scheme for Protecting IP in Diffusion Models
Yingsha Xie, Rui Min, Zeyu Qin, Fei Ma, Li Shen, Fei Richard Yu, Xiaochun Cao
摘要
Preserving intellectual property (IP) within a pre-trained diffusion model is critical for protecting the model’s copyright and preventing unauthorized model deployment. In this regard, model watermarking is a common practice for IP protection that embeds traceable information within models and allows for further verification. Nevertheless, existing watermarking schemes often face challenges due to their vulnerability to fine-tuning, limiting their practical application in general pre-training and fine-tuning paradigms. Inspired by using mode connectivity to analyze model performance between a pair of connected models, we investigate watermark vulnerability by leveraging Linear Mode Connectivity (LMC) as a proxy to analyze the fine-tuning dynamics of watermark performance. Our results show that existing watermarked models tend to converge to sharp minima in the loss landscape, thus making them vulnerable to fine-tuning. To tackle this challenge, we propose RoMa, a Ro bust M odel w a termarking scheme that improves the robustness of watermarks against fine-tuning. Specifically, RoMa decomposes watermarking into two components, including Embedding Functionality , which preserves reliable watermark detection capability, and Path-specific Smoothness , which enhances the smoothness along the watermark-connected path to improve robustness. Extensive experiments on benchmark datasets MS-COCO-2017 and CUB-200-2011 demonstrate that RoMa significantly improves watermark robustness against fine-tuning while maintaining generation quality, outperforming baselines. The code is available at https://github.com/xiekks/RoMa .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper43
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh 等ICML 2021 · 被引用 47,906 次
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu 等ICLR 2022 · 被引用 18,833 次
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 被引用 13,211 次
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
相关 Paper
- WMAdapter: Adding WaterMark Control to Latent Diffusion ModelsHai Ci, Yiren Song, Pei Yang, Jinheng Xie 等ICML 2025
- Your Text Encoder Can Be an Object-Level Watermarking ControllerNaresh Kumar Devulapally, Mingzhen Huang, Vishal Asnani, Shruti Agarwal 等ICCV 2025 · 被引用 1 次
- Attack-Resilient Image Watermarking Using Stable DiffusionLijun Zhang, Xiao Liu, Antoni Viros Martin, Cindy Xiong Bearfield 等NeurIPS 2024 · 被引用 62 次
- SleeperMark: Towards Robust Watermark against Fine-Tuning Text-to-image Diffusion ModelsZilan Wang, Junfeng Guo, Jiacheng Zhu, Yiming Li 等CVPR 2025
- MOLM: Mixture of LoRA MarkersSamar Fares, Nurbek Tastan, Noor Hazim Hussein, Karthik NandakumarICLR 2026
