arXiv論文メモ
新着一覧
cs.IT / cs.LG / math.IT · 査読状況未確認

生成結果の分布を保つ電子透かしの情報量限界を解析

On the Information-Theoretic Limits of Latent-Space Watermarking Through Pretrained Generators

Jinwan Jeon, Minju Lee, and Sung Hoon Lim

この論文をやさしく読む

ひとことで言うと

生成物の見た目に関係する確率分布を厳密に変えず、秘密の識別情報をどれだけ埋め込めるかを数学的に調べています。生成し直す攻撃によって、その情報量がどう減るかも対象です。

何に役立つ?

透かしに必要な秘密鍵の量と、埋め込める情報量の関係を設計する際の理論的な基準になります。生成物の分布保持と再生成への強さを同時に考えるための枠組みです。

この研究の面白いところ

透かしを出力へ直接付けるのではなく、既存生成器の潜在入力を選ぶという制約を扱います。多次元ガウスモデルでは鍵を各モードへどう配分するかまで解析しています。

どこまで分かった?

容量領域の厳密な特定には、潜在入力分布の一意性などの条件があります。再生成攻撃に関する結果も指定されたガウスモデルに対する理論解析で、任意の実用生成AIに同じ耐性を保証するものではありません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

本研究では、レンダラーと呼ぶ所定の潜在変数から出力への確率的写像を用いて、事前学習済み生成器を介した潜在空間の電子透かしを調べる。透かしの符号器は、メッセージと秘密鍵を使って潜在入力を選ぶ。すべてのメッセージと意味的文脈について、公開される出力は、望まれる条件付き出力分布と厳密に同じ分布を持たなければならない。有限アルファベットについて、通信レートと鍵の資源量の内界・外界を導き、所定の潜在インターフェースを通じて透かし通信を実現するための符号化と協調の要件を特徴づける。 生成器の目標出力分布が、レンダラーを通じて対応する潜在入力分布を一意に定める場合、強化された逆定理から容量領域を得る。同じ領域は、事前学習時の潜在分布を明示的に保持する場合にも適用される。解析を一般の同時ガウスモデルへ拡張し、生成出力で利用可能な透かし情報と、その目標分布を保つために必要な潜在変数側の協調の双方を捉える、潜在変数の十分統計量を特定する。ベクトルガウスモデルでは、さらに、得られた各モードに秘密鍵の資源を最適に割り当てる方法を特徴づける。 最後に、生成型の透かしにとりわけ自然に生じる、新たな頑健性上の脅威を扱う。攻撃者は公開されたサンプルを再生成し、埋め込まれた透かしを弱めたり壊したりしながら、同じ基底内容の新しい実現を得ることができる。この頑健性の軸を枠組みに取り込み、意味的文脈が符号器には既知だが検出器には隠され、再生成攻撃がその文脈に依存してよい場合について、スカラーガウスモデルの1回の再生成に対する複合通信路容量を特徴づける。さらに、正準的な再生成が複数回繰り返される場合へ解析を拡張し、それに伴う透かし容量の減衰を特徴づける。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-21(UTC)
最新改訂
2026-09-21 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

We study latent-space watermarking through a pretrained generator using a prescribed latent-to-output stochastic mapping, called the renderer. A watermark encoder selects the latent input using a message and secret key. For every message and semantic context, the released output must have exactly the desired conditional output distribution. For finite alphabets, we derive rate--key inner and outer bounds and characterize the coding and coordination requirements for realizing watermark communication through the prescribed latent interface. When the target output distribution of the generator uniquely determines the corresponding latent input distribution through the renderer, a strengthened converse yields the capacity region; the same region governs explicit preservation of the pretrained latent distribution. We extend the analysis to general jointly Gaussian models and identify a sufficient statistic of the latent that captures both the watermark-bearing information available at the generated output and the latent coordination required to preserve its target distribution. For the vector Gaussian model, we further characterize the optimal allocation of the secret-key resource across the resulting modes. Finally, we turn to an emerging robustness threat that is particularly natural in generative watermarking: an adversary can regenerate the released sample to obtain a fresh realization of the same underlying content while attenuating or destroying the embedded watermark. We incorporate this robustness axis into our framework and characterize the one-pass compound capacity of the scalar Gaussian model when the semantic context is known to the encoder but hidden from the detector, while the regeneration attack may depend on that context. Extending the analysis to multiple rounds of repeated canonical regeneration, we characterize the resulting watermark-capacity decay.

著者のコメント

Submitted to the IEEE Transactions on Information Theory for possible publication

arXiv ID: 2609.24377 / 要約の誤りについて