Data Provenance for Image Auto-Regressive Generation

📅 2026-06-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the lack of reliable provenance mechanisms for image autoregressive (IAR) generative models by proposing a post-hoc attribution framework that requires neither modifications to the generation pipeline nor embedded watermarks. The method leverages intrinsic autoregressive patterns present in IAR-generated images to identify their source model after publication. Without relying on model alterations or auxiliary annotations, the framework demonstrates high accuracy and strong robustness across multiple state-of-the-art IAR architectures. To the best of our knowledge, this is the first approach capable of effectively tracing existing IAR-generated content, offering a practical technical pathway for combating disinformation and enabling accountability for harmful synthetic media.
📝 Abstract
Image autoregressive models (IARs) have recently demonstrated remarkable capabilities in visual content generation, achieving photorealistic quality and rapid synthesis through the next-token prediction paradigm adapted from large language models. As these models become widely accessible, robust data provenance is required to reliably trace IAR-generated images to the source model that synthesized them. This is critical to prevent the spread of misinformation, detect fraud, and attribute harmful content. We find that although IAR-generated images often appear visually identical to real images, their generation process introduces characteristic patterns in their outputs, which serves as a reliable provenance signal for the generated images. Leveraging this, we present a post-hoc framework that enables the robust detection of such patterns for provenance tracing. Notably, our framework does not require modifications of the generative process or outputs. Thereby, it is applicable in contexts where prior watermarking methods cannot be used, such as for generated content that is already published without additional marks and for models that do not integrate watermarking. We demonstrate the effectiveness of our approach across a wide range of IARs, highlighting its high potential for robust data provenance tracing in autoregressive image generation.
Problem

Research questions and friction points this paper is trying to address.

data provenance
image autoregressive generation
source tracing
misinformation detection
AI-generated images
Innovation

Methods, ideas, or system contributions that make the work stand out.

data provenance
image autoregressive models
post-hoc detection
generation fingerprinting
watermark-free tracing
💼 Related Jobs
No related jobs found.
B
Bihe Zhao
CISPA Helmholtz Center for Information Security
L
Louis Kerner
CISPA Helmholtz Center for Information Security
M
Michel Meintz
CISPA Helmholtz Center for Information Security
T
Tameem Bakr
CISPA Helmholtz Center for Information Security
Franziska Boenisch
Franziska Boenisch
Assistant Professor, CISPA Helmholtz Center for Information Security
privacysecuritymachine learningprivacy preserving machine learningdifferential privacy
Adam Dziedzic
Adam Dziedzic
SprintML group at CISPA, Vector Institute & University of Toronto
Trustworthy ML