arXiv Machine Learning

On the Information-Theoretic Limits of Latent-Space Watermarking Through Pretrained Generators

The paper investigates latent‑space watermarking using pretrained generators, where a watermark encoder selects latent inputs based on a message and secret key to produce outputs with a specified conditional distribution. For finite alphabets, it derives inner and outer bounds on the rate–key trade‑off and characterizes the capacity region when the generator’s output uniquely determines the latent distribution. The study extends to jointly Gaussian models, identifies key sufficient statistics, optimally allocates secret‑key resources across modes, and analyzes robustness against regeneration attacks, providing compound capacity results and decay rates for repeated attacks.

arXiv AI
Aug 12

MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent Manipulation

arXiv:2608. 10166v1 Announce Type: cross Abstract: Digital watermarking has emerged as a critical technique for provenance and copyright attribution in AI-generated imagery, yet its robustness against realistic, model-agnostic removal attacks remains poorly explored.

By Jie Cao, Qi Li, Zelin Zhang, Xiaodong Wu, Lingshuang Liu, Xiangman Li, Jianbing Ni
arXiv AI
2d ago

Exploring Weaknesses of Generative Image Watermarks against Latent Frequency Masking

arXiv:2610.02010v1 Announce Type: cross Abstract: Invisible watermarking has become a central tool for tracing AI-generated images, but its robustness against adaptive removal attacks remains an open...

By Kirill Aistov, Khaled Abud, Irina Serzhenko, Egor Kovalev, Aleksey Yakushev, Aleksandr Akimenkov, Dmitry Obydenkov, Yury Markin, Sergey Lavrushkin, Dmitriy Vatolin, Anastasia Antsiferova
Hugging Face Trending Papers
Jul 30

SPFM-Net: Semantic-Prior-Guided Frequency-Constrained Mamba for Invisible Watermark Attack

Existing watermark attacks typically rely on predefined signal-processing operations or locally constrained restoration networks, making it difficult to capture the long-range dependencies of globally distributed watermark signals and resulting in an unfavorable trade-off between removal effectiveness and visual fidelity. In this paper, we propose SPFM-Net, a semantic-prior-guided and frequency-constrained Mamba framework for invisible watermark attack.

arXiv Computation and Language
4d ago

TTMark: Pairwise Distortion-Free Watermarking Beyond Single-Token Entropy

TTMark introduces a pairwise watermarking framework that extends distortion‑free watermarking from single tokens to adjacent token pairs, enlarging the watermarking alphabet from V to V². By watermarking the joint distribution of consecutive tokens, the detector can exploit both token entropy and conditional entropy while maintaining distortion‑freeness. Experiments on multiple language models and datasets show that TTMARK improves detectability, robustness to edits, and localized watermark detection without degrading generation quality.

By Ruibo Chen, Zhengmian Hu, Donghang Lu, Xuehao Cui, Georgios Milis, Yihan Wu, Jian Du, Heng Huang
arXiv Machine Learning
Aug 27

MeMark: Membrane-Space Watermarking for Spiking Neural Networks

MeMark introduces a watermarking scheme for Spiking Neural Networks that embeds a multi‑bit identifier directly into the membrane state of selected Leaky Integrate‑and‑Fire neurons, rather than in the output head. The watermark is recoverable by comparing neuron firing thresholds, eliminating the need for a learned decoder. Experiments on various SNN architectures—including a 215.4M‑parameter SpikeGPT checkpoint—show that all 20 independent 64‑bit keys reliably pass verification under a 51/64 rule, remain robust after fine‑tuning, pruning, quantization, and output‑head replacement, and are not recovered by random keys or adaptive attacks within the tested threat model.

By Roberto Ria\~no, Gorka Abad, Stjepan Picek, Aitor Urbieta
arXiv Computer Vision
Aug 27

IRIS: Visual-Semantic Binding for Forgery-Resistant Watermarking of Diffusion Images

IRIS is a training‑free watermarking scheme for diffusion‑generated images that binds a watermark to the image’s visual semantics. It derives an intrinsic ring identifier from a content code of the non‑watermarked image and injects it late in the generation trajectory, ensuring the mark survives common processing while breaking under semantic changes or foreign images. Experiments on three prompt datasets show IRIS reliably detects watermarks, maintains fidelity to the original image, and resists forgery techniques that defeat other marks.

By Xiaoyan Feng, Zheng Gao, Tong Guan, Rui Bao, Bokang Zeng, Xiaoyu Li, Jiaojiao Jiang