Skip to content
Conference Open access

Latents-Inv:Robust Semantic Watermark via Dual-Path Mutual Information Redundancy for Diffusion Models

Sep 2026 · Proceedings of the Thirty-Fifth International Joint Conference on Artificial Intelligence · pp. 661-669 · 0 citations · 41 references

TL;DR

A dual-path network is proposed to encode watermark information into both the generated image and the owner’s secret key, which achieves superior robustness against various adversarial attacks while maintaining high visual quality across diverse generative models.

Abstract

Semantic watermarking methods, embedding identity into the initial latent noise, provide an imperceptible identity traceability for diffusion models in copyright protection and source verification. However, existing methods are highly vulnerable to adversarial attacks, especially geometric transformations (e.g., rotation, cropping) and latent-space manipulations via proxy models, limiting the reliability of watermark verification in practical deployment. To address this issue, we propose a robust and fully reversible, flow-based watermarking framework with dual encoding paths, which preserves high visual fidelity of watermarked image while ensuring resilient identity recovery under adversarial attacks. Specifically, a dual-path network is proposed to encode watermark information into both the generated image and the owner’s secret key. This network leverages Mutual Information Redundancy to recover compromised information under single-path attack, ensuring robust verification. To enhance verification credibility without degrading generation quality, we introduce a joint training strategy that suppresses false positives on negative samples through contrastive learning under fidelity constraints. Furthermore, we employ a backward Euler iteration scheduler for rectified flow models, which facilitate accurate inversion mapping, to enable effective watermark verification, which accurate inversion. Extensive experiments show that our method achieves superior robustness against various adversarial attacks while maintaining high visual quality across diverse generative models.

Read PDF

Similar papers

Preprint Sep 2026

FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models

Text-to-image diffusion models enable data-efficient"mimicry"attacks, wherein adversaries fine-tune the model on a handful of public photos to synthesize convincing forgeries of a target individual. A common countermeasure is to embed imperceptible, low-energy watermarks, yet recent studies show these signatures are br...

Hao-Yang Li, Ruo-Xi Sun, Qing-Qing Ye et al. · 0 citations
Open access Sep 2026

FakeMark: gradient-guided false watermark claims via robust feature fusion

Model watermarking supports intellectual-property claims by verifying a model’s responses to a secret key set, but this behavior-only interface is vulnerable to fabricated evidence. This work presents FakeMark, a gradient-guided false-claim attack for image classifiers that uses a white-box surrogate but never queries...

Yu-Tong Wu, Wen-Yue Li, He-Wang Nie et al. · 0 citations
Aug 2026

ROBIN++: Unified Copyright Protection and Tamper Localization for Diffusion Models Via Dual-Domain Synergistic Watermarking.

Digital watermarking provides a promising solution for verifying the provenance and integrity of generated content. However, existing methods often suffer from an inherent trade-off between copyright robustness and localization sensitivity due to the entanglement of conflicting signals within a single domain. In this p...

Huayang Huang, Siqi Zeng, Qian Wang et al. · 0 citations
Conference Sep 2026

Encrypted deep robust reversible image watermarking with preset private key

Robust reversible watermarking (RRW) is an important branch of digital watermarking, which supports lossless recovery of original watermarks in lossless channels, while ensuring reliable watermark extraction against various distortions and attacks in lossy channels. However, existing deep learning-based RRW methods sti...

Zi-Xuan Zhang, Chunqiang Yu, Xian-Quan Zhang et al. · 0 citations
Preprint Aug 2026

MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent Manipulation

Digital watermarking has emerged as a critical technique for provenance and copyright attribution in AI-generated imagery, yet its robustness against realistic, model-agnostic removal attacks remains poorly explored. Existing attacks either succeed only against specific generative models or achieve removal at the cost...

Jie Cao, Qi Li, Zelin Zhang et al. · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.