GaussianMarker: Uncertainty-Aware Copyright Protection of 3D Gaussian Splatting
About
3D Gaussian Splatting (3DGS) has become a crucial method for acquiring 3D assets. To protect the copyright of these assets, digital watermarking techniques can be applied to embed ownership information discreetly within 3DGS models. However, existing watermarking methods for meshes, point clouds, and implicit radiance fields cannot be directly applied to 3DGS models, as 3DGS models use explicit 3D Gaussians with distinct structures and do not rely on neural networks. Naively embedding the watermark on a pre-trained 3DGS can cause obvious distortion in rendered images. In our work, we propose an uncertainty-based method that constrains the perturbation of model parameters to achieve invisible watermarking for 3DGS. At the message decoding stage, the copyright messages can be reliably extracted from both 3D Gaussians and 2D rendered images even under various forms of 3D and 2D distortions. We conduct extensive experiments on the Blender, LLFF and MipNeRF-360 datasets to validate the effectiveness of our proposed method, demonstrating state-of-the-art performance on both message decoding accuracy and view synthesis quality.
Related benchmarks
| Task | Dataset | Result | Rank | |
|---|---|---|---|---|
| Digital Watermarking | Blender and LLFF (test) | Bit Accuracy (No Attack)99.36 | 15 | |
| 3D Scene Watermarking | Blender and LLFF 32 bits | Bit Accuracy98.85 | 14 | |
| 3D Scene Watermarking | Blender and LLFF 48 bits | Bit Acc98.25 | 14 | |
| 3D Scene Watermarking | Blender and LLFF 16 bits | Bit Accuracy99.36 | 14 | |
| 3D Watermarking | LLFF and Blender (train) | Training Time (min)3 | 6 | |
| Image Quality Assessment | Blender and LLFF views (test) | SSIM0.906 | 6 | |
| 3D Watermarking Robustness against Diffusion Attacks | Blender and LLFF (test) | Bit Accuracy (Deterministic)0.587 | 6 | |
| 3D Gaussian watermarking and message extraction | Blender, LLFF, and MipNeRF360 average | L1 Difference3.00e-5 | 5 | |
| 3D Scene Watermarking and Reconstruction | Blender | PSNR31.53 | 5 | |
| 3D Scene Watermarking and Reconstruction | LLFF | PSNR28.61 | 5 |