{"id":"https://openalex.org/W4413145730","doi":"https://doi.org/10.1109/cvpr52734.2025.00769","title":"SleeperMark: Towards Robust Watermark against Fine-Tuning Text-to-image Diffusion Models","display_name":"SleeperMark: Towards Robust Watermark against Fine-Tuning Text-to-image Diffusion Models","publication_year":2025,"publication_date":"2025-06-10","ids":{"openalex":"https://openalex.org/W4413145730","doi":"https://doi.org/10.1109/cvpr52734.2025.00769"},"language":"en","primary_location":{"id":"doi:10.1109/cvpr52734.2025.00769","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52734.2025.00769","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5087828525","display_name":"Zilan Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Zilan Wang","raw_affiliation_strings":["NTU"],"affiliations":[{"raw_affiliation_string":"NTU","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100584999","display_name":"Junfeng Guo","orcid":"https://orcid.org/0009-0002-2046-9386"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Junfeng Guo","raw_affiliation_strings":["University of Maryland"],"affiliations":[{"raw_affiliation_string":"University of Maryland","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101186958","display_name":"Jiacheng Zhu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jiacheng Zhu","raw_affiliation_strings":["MIT CSAIL"],"affiliations":[{"raw_affiliation_string":"MIT CSAIL","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100346332","display_name":"Yiming Li","orcid":"https://orcid.org/0000-0002-2258-265X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yiming Li","raw_affiliation_strings":["NTU"],"affiliations":[{"raw_affiliation_string":"NTU","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101589485","display_name":"Heng Huang","orcid":"https://orcid.org/0000-0002-8387-8980"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Heng Huang","raw_affiliation_strings":["University of Maryland"],"affiliations":[{"raw_affiliation_string":"University of Maryland","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102861481","display_name":"Muhao Chen","orcid":"https://orcid.org/0000-0003-0118-3147"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Muhao Chen","raw_affiliation_strings":["UC Davis"],"affiliations":[{"raw_affiliation_string":"UC Davis","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5015173810","display_name":"Zhengzhong Tu","orcid":"https://orcid.org/0000-0002-7594-2292"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhengzhong Tu","raw_affiliation_strings":["Texas A&amp;M University"],"affiliations":[{"raw_affiliation_string":"Texas A&amp;M University","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5087828525"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":5.8468,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.9634645,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"8213","last_page":"8224"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11017","display_name":"Chaos-based Image/Signal Encryption","score":0.9624999761581421,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12707","display_name":"Vehicle License Plate Recognition","score":0.9456999897956848,"subfield":{"id":"https://openalex.org/subfields/2214","display_name":"Media Technology"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.7892674207687378},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6793178915977478},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.6080218553543091},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6038171052932739},{"id":"https://openalex.org/keywords/diffusion","display_name":"Diffusion","score":0.5499937534332275},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.5226925611495972},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5194960832595825},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3387260437011719},{"id":"https://openalex.org/keywords/physics","display_name":"Physics","score":0.09570994973182678}],"concepts":[{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.7892674207687378},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6793178915977478},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.6080218553543091},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6038171052932739},{"id":"https://openalex.org/C69357855","wikidata":"https://www.wikidata.org/wiki/Q163214","display_name":"Diffusion","level":2,"score":0.5499937534332275},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.5226925611495972},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5194960832595825},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3387260437011719},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.09570994973182678},{"id":"https://openalex.org/C97355855","wikidata":"https://www.wikidata.org/wiki/Q11473","display_name":"Thermodynamics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cvpr52734.2025.00769","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52734.2025.00769","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W2137394636","https://openalex.org/W2358993821","https://openalex.org/W1516446231","https://openalex.org/W2098152888","https://openalex.org/W1559740347","https://openalex.org/W2040356834","https://openalex.org/W2080353903","https://openalex.org/W2381486749","https://openalex.org/W2385289568","https://openalex.org/W2367449261"],"abstract_inverted_index":{"Recent":[0],"advances":[1],"in":[2,86],"large-scale":[3],"text-to-image":[4],"(T2I)":[5],"diffusion":[6,59,141,188,192,199],"models":[7,17,48,60,193,200],"have":[8],"enabled":[9],"a":[10,121,131],"variety":[11],"of":[12,182,187],"downstream":[13,174,206],"applications.":[14,53],"As":[15],"T2I":[16,140],"require":[18],"extensive":[19,177],"resources":[20],"for":[21,30,39,49,58],"training,":[22],"they":[23],"constitute":[24],"highly":[25],"valued":[26],"intellectual":[27],"property":[28],"(IP)":[29],"their":[31],"legitimate":[32],"owners,":[33],"yet":[34],"making":[35],"them":[36],"incentive":[37],"targets":[38],"unauthorized":[40],"fine-tuning":[41,207],"by":[42],"adversaries":[43],"seeking":[44],"to":[45,110,120,135,148,162,169,172],"leverage":[46],"these":[47,81],"customized,":[50],"usually":[51],"profitable":[52],"Existing":[54],"IP":[55],"protection":[56],"methods":[57],"generally":[61],"involve":[62],"embedding":[63],"watermark":[64,115,151,166],"patterns":[65],"and":[66,95,197,208,215],"then":[67],"verifying":[68],"ownership":[69],"through":[70],"generated":[71],"outputs":[72],"examination,":[73],"or":[74],"inspecting":[75],"the":[76,90,96,112,146,150,154,160,164,180,213,222],"model\u2019s":[77,223],"feature":[78,97],"space.":[79],"However,":[80],"techniques":[82],"are":[83],"inherently":[84],"ineffective":[85],"practical":[87],"scenarios":[88],"when":[89,117],"watermarked":[91],"model":[92,107,147,161,216],"undergoes":[93],"fine-tuning,":[94],"space":[98],"is":[99,108,228],"inaccessible":[100],"during":[101],"verification":[102],"(i.e.,":[103],"black-box":[104],"setting).":[105],"The":[106,226],"prone":[109],"forgetting":[111],"previously":[113],"learned":[114],"knowledge":[116],"it":[118,157],"adapts":[119],"new":[122,173],"task.":[123],"To":[124],"address":[125],"this":[126],"challenge,":[127],"we":[128],"propose":[129],"SleeperMark,":[130],"novel":[132],"framework":[133],"designed":[134],"embed":[136],"resilient":[137],"watermarks":[138],"into":[139],"models.":[142],"SleeperMark":[143,183],"explicitly":[144],"guides":[145],"disentangle":[149],"information":[152],"from":[153],"semantic":[155],"concepts":[156],"learns,":[158],"allowing":[159],"retain":[163],"embedded":[165],"while":[167],"continuing":[168],"be":[170],"adapted":[171],"tasks.":[175],"Our":[176],"experiments":[178],"demonstrate":[179],"effectiveness":[181],"across":[184],"various":[185,209],"types":[186],"models,":[189],"including":[190],"latent":[191],"(e.g.,":[194,201],"Stable":[195],"Diffusion)":[196],"pixel":[198],"DeepFloyd-IF),":[202],"showing":[203],"robustness":[204],"against":[205],"attacks":[210],"at":[211,230],"both":[212],"image":[214],"levels,":[217],"with":[218],"minimal":[219],"impact":[220],"on":[221],"generative":[224],"capability.":[225],"code":[227],"available":[229],"https://github.com/taco-group/SleeperMark.":[231]},"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":1}],"updated_date":"2026-04-19T08:26:33.389920","created_date":"2025-10-10T00:00:00"}
