Pith. sign in

REVIEW 7 cited by

A Recipe for Watermarking Diffusion Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2303.10137 v2 pith:KDQD7YEZ submitted 2023-03-17 cs.CV cs.CRcs.LG

classification cs.CVcs.CRcs.LG
keywords watermarkingdiffusionrecipecontentcopyrightmodelsmonitoringprotection
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Diffusion models (DMs) have demonstrated advantageous potential on generative tasks. Widespread interest exists in incorporating DMs into downstream applications, such as producing or editing photorealistic images. However, practical deployment and unprecedented power of DMs raise legal issues, including copyright protection and monitoring of generated content. In this regard, watermarking has been a proven solution for copyright protection and content monitoring, but it is underexplored in the DMs literature. Specifically, DMs generate samples from longer tracks and may have newly designed multimodal structures, necessitating the modification of conventional watermarking pipelines. To this end, we conduct comprehensive analyses and derive a recipe for efficiently watermarking state-of-the-art DMs (e.g., Stable Diffusion), via training from scratch or finetuning. Our recipe is straightforward but involves empirically ablated implementation details, providing a foundation for future research on watermarking DMs. The code is available at https://github.com/yunqing-me/WatermarkDM.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 7 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. RaMark: Radioactive Watermarking for Generated Tabular Data

    cs.CR 2026-07 conditional novelty 7.0 of 10

    A sinusoidal dependency embedded as part of the tabular distribution remains detectable after generative retraining and data-modification attacks while utility is preserved.

  2. Beyond Invisibility: Learning Robust Visible Watermarks for Stronger Copyright Protection

    cs.LG 2025-06 conditional novelty 7.0 of 10

    HARVIM learns watermark placement to maximize reconstruction error under an inpainting-based removal model, showing modest gains over random watermarks.

  3. Autoregressive Images Watermarking through Lexical Biasing: An Approach Resistant to Regeneration Attack

    cs.CR 2025-06 conditional novelty 6.0 of 10

    LBW embeds watermarks into autoregressive image token maps by biasing token sampling toward a secret green list and detects them with a z-test on green-token counts.

  4. Position: AI/ML Deepfake Research is Misaligned with AI-Generated Non-Consensual Intimate Imagery (AIG-NCII)

    cs.AI 2026-05 conditional novelty 5.0 of 10

    The dominant real-world use of generative-image abuse is non-consensual intimate imagery, yet the AI/ML research field focuses almost exclusively on viewer deception.

  5. Evaluating Dataset Watermarking for Fine-tuning Traceability of Customized Diffusion Models: A Comprehensive Benchmark and Removal Approach

    cs.CV 2025-11 conditional novelty 5.0 of 10

    Existing dataset watermarks for diffusion fine-tuning transfer well across models and tasks but remain vulnerable to a proposed restoration-based removal attack (DeAttack), whose claimed full removal is not fully demo...

  6. Traceable TTS: Toward Watermark-Free TTS with Strong Traceability

    eess.AS 2025-07 reject novelty 5.0 of 10

    A joint training loop makes an F5-TTS model produce audio that a paired wav2vec 2.0/LCNN discriminator can recognize, enabling watermark-free attribution; however, the reported generalization gain is not isolated from...

  7. KGMark: A Diffusion Watermark for Knowledge Graphs

    cs.CR 2025-05 reject novelty 5.0 of 10

    KGMark embeds a detectable watermark into knowledge graph embeddings via diffusion inversion, with graph alignment and a learned mask, and reports high AUC under editing attacks.

Pith tools