Pith. sign in

REVIEW 2 cited by

Securing Deep Generative Models with Universal Adversarial Signature

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2305.16310 v1 pith:6HCRMZVG submitted 2023-05-25 cs.CV

classification cs.CV
keywords signaturegenerativemodelsadversarialgeneratorimagesuniversalarbitrary
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recent advances in deep generative models have led to the development of methods capable of synthesizing high-quality, realistic images. These models pose threats to society due to their potential misuse. Prior research attempted to mitigate these threats by detecting generated images, but the varying traces left by different generative models make it challenging to create a universal detector capable of generalizing to new, unseen generative models. In this paper, we propose to inject a universal adversarial signature into an arbitrary pre-trained generative model, in order to make its generated contents more detectable and traceable. First, the imperceptible optimal signature for each image can be found by a signature injector through adversarial training. Subsequently, the signature can be incorporated into an arbitrary generator by fine-tuning it with the images processed by the signature injector. In this way, the detector corresponding to the signature can be reused for any fine-tuned generator for tracking the generator identity. The proposed method is validated on the FFHQ and ImageNet datasets with various state-of-the-art generative models, consistently showing a promising detection rate. Code will be made publicly available at \url{https://github.com/zengxianyu/genwm}.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Crack in the Bark: Leveraging Public Knowledge to Remove Tree-Ring Watermarks

    cs.CR 2025-06 conditional novelty 6.0 of 10

    VAE-recovered latent surrogates make Tree-Ring watermarks removable: ROC-AUC drops from 0.993 to 0.153 with little image quality loss.

  2. When There Is No Decoder: Removing Watermarks from Stable Diffusion Models in a No-box Setting

    cs.CR 2025-07 reject novelty 4.0 of 10

    Blur-plus-deblur and generator fine-tuning can push watermark bit accuracy toward chance, but only when the attacker can train a surrogate decoder that matches the target's architecture.

Pith tools