Gaussian Carrier: Model-Level Watermarking in Feed-Forward 3D Gaussian Splatting
Abstract
Feed-forward 3D Gaussian Splatting (3DGS) models are increasingly deployed as reusable pretrained reconstruction engines, yet their editable parameters introduce an underexplored model-level risk: an attacker can encode an attacker-specified invisible message into novel view renderings through lightweight fine-tuning of the Gaussian prediction head, without perturbing the input images or retraining the full model. We investigate this model-level attack surface through adversarial watermark injection. Naively fine-tuning the Gaussian prediction head, however, modifies predicted primitives at all spatial locations, resulting in unnecessary representation changes and degrading the rendering fidelity. To address this, we propose Gaussian Carrier, which identifies reliable watermark carriers according to opacity and cross-view observability. We develop a carrier-restricted mechanism that applies the adapted predictions only to selected primitives while retaining the original pretrained predictions. Combined with complementary watermark-success and fidelity-preserving objectives, the predictions are optimized. Experiments on RealEstate10K and ACID datasets with two feed-forward 3DGS models achieve over watermarking accuracy while limiting the PSNR difference to at most dB. The watermarking approach also maintains above accuracy under various distortions. These results expose Gaussian adaptation as a model-level attack surface in pretrained feed-forward 3DGS.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.