arXiv · 2604.16363
CSF: Black-box Fingerprinting via Compositional Semantics for Text-to-Image Models
Abstract
Text-to-image models are commercially valuable assets often distributed under restrictive licenses, but such licenses are enforceable only when violations can be detected. Existing methods require pre-deployment watermarking or internal model access, which are unavailable in commercial API deployments. We present Compositional Semantic Fingerprinting (CSF), the first black-box method for attributing fine-tuned text-to-image models to protected lineages using only query access. CSF treats models as semantic category generators and probes them with compositional underspecified prompts that remain rare under fine-tuning. This gives IP owners an asymmetric advantage: new prompt compositions can be generated after deployment, while attackers must anticipate and suppress a much broader space of fingerprints. Across 6 model families (FLUX, Kandinsky, SD1.5/2.1/3.0/XL) and 13 fine-tuned variants, our Bayesian attribution framework enables controlled-risk lineage decisions, with all variants satisfying the dominance criterion.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Junhoo Lee, Mijin Koo, Nojun Kwak. 2026-03-20. CSF: Black-box Fingerprinting via Compositional Semantics for Text-to-Image Models. https://arxiv.org/abs/2604.16363
Cite the original work for its findings. Save a collection to share your selection of sources.