SpectralCanary: Embarrassingly Simple Low-Frequency Traces for T2I Dataset-Use Auditing
Sy Tuyen Ho ⋅ Anirudh Satheesh ⋅ Soham Chawathe ⋅ Huy Nghiem ⋅ Furong Huang
Abstract
Auditing whether a text-to-image (T2I) model was fine-tuned on a particular image collection is difficult: a model can absorb collection-level visual characteristics without reproducing training images. Proactive dataset-use auditing plants a shared trace before release and later tests model generations for its transfer. Existing approaches often trade off verifiability, fidelity, robustness, and deployability. We introduce \textbf{SpectralCanary}, which uses a smooth low-pass mask to blend a fixed canary image into every collection image while leaving captions unchanged and requiring neither auxiliary generation nor per-image optimization. A lightweight verifier detects the transferred trace in suspect-model outputs. Across eight model--transformation settings on Pokemon, spanning two architecture families and three realistic data transformations, SpectralCanary achieves the highest average among the evaluated methods with $98.0\%$ AUC and $91.1\%$ TPR at a $1\%$ false-positive rate. Across five artistic, medical, satellite, fashion datasets with SD3.5, SpectralCanary averages $99.5\%$ AUC and $92.4\%$ TPR while preserving the released images (SSIM $0.989$, LPIPS $0.022$) with no consistent FID degradation (mean $\Delta$FID $0.05$). In matched-energy ablations on Pokemon and ROCOv2, we show that low-frequency placement transfers more reliably compared to mid/high-frequency placement. Within the evaluated adaptive attacks, effective removal requires aggressive modification and incurs more than $25$ $\Delta$FID points. These results identify low-frequency visual structure as an effective carrier for collection-level T2I audit traces.
Chat is not available.
Successful Page Load