Pith. sign in

REVIEW 8 cited by

An Undetectable Watermark for Generative Image Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2410.07369 v4 pith:B5NOWCO3 submitted 2024-10-09 cs.CR cs.AIcs.LGcs.MM

classification cs.CRcs.AIcs.LGcs.MM
keywords watermarkimageimagesqualityschemeundetectableattacksbits
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We present the first undetectable watermarking scheme for generative image models. Undetectability ensures that no efficient adversary can distinguish between watermarked and un-watermarked images, even after making many adaptive queries. In particular, an undetectable watermark does not degrade image quality under any efficiently computable metric. Our scheme works by selecting the initial latents of a diffusion model using a pseudorandom error-correcting code (Christ and Gunn, 2024), a strategy which guarantees undetectability and robustness. We experimentally demonstrate that our watermarks are quality-preserving and robust using Stable Diffusion 2.1. Our experiments verify that, in contrast to every prior scheme we tested, our watermark does not degrade image quality. Our experiments also demonstrate robustness: existing watermark removal attacks fail to remove our watermark from images without significantly degrading the quality of the images. Finally, we find that we can robustly encode 512 bits in our watermark, and up to 2500 bits when the images are not subjected to watermark removal attacks. Our code is available at https://github.com/XuandongZhao/PRC-Watermark.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 8 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Radioactive Watermarks in Diffusion and Autoregressive Image Generative Models

    cs.LG 2025-06 conditional novelty 7.0 of 10

    Green/red-list token watermarking survives fine-tuning in autoregressive image models, while latent-diffusion watermarks do not survive the autoencoder or the training noise process.

  2. FARI: Robust One-Step Inversion for Watermarking in Diffusion Models

    cs.CR 2026-07 accept novelty 6.0 of 10

    One-step adversarially LoRA-tuned inversion exploits low-curvature reverse trajectories to beat 50-step DDIM on watermark robustness after ~20 minutes of fine-tuning.

  3. ROMS-IMLE: A Minimalist Approach to Competitive Single-Step Generative Modelling

    cs.LG 2026-07 conditional novelty 6.0 of 10

    A single-step IMLE generator with per-stage supervision and a robust loss reports FID 2.56 on ImageNet-256 by filtering ~5% of samples at test time.

  4. ShapeMark: Robust and Diversity-Preserving Watermarking for Diffusion Models

    cs.CR 2026-03 conditional novelty 6.0 of 10

    ShapeMark embeds watermark bits as block-level permutations of a key-derived Gaussian noise latent, achieving higher robustness and diversity than prior noise-as-watermark methods.

  5. IConMark: Robust Interpretable Concept-Based Watermark For AI Images

    cs.CV 2025-07 conditional novelty 6.0 of 10

    IConMark adds preselected, human-readable objects to AI images via prompt engineering and detects them with a vision-language model, achieving higher AUROC than noise-based watermarks on tested augmentations.

  6. A Watermark for Auto-Regressive Image Generation Models

    cs.CV 2025-06 conditional novelty 6.0 of 10

    Clustering visual tokens into equivalence classes lets a distortion-free reweight watermark survive the retokenization step in auto-regressive image generation.

  7. A Crack in the Bark: Leveraging Public Knowledge to Remove Tree-Ring Watermarks

    cs.CR 2025-06 conditional novelty 6.0 of 10

    VAE-recovered latent surrogates make Tree-Ring watermarks removable: ROC-AUC drops from 0.993 to 0.153 with little image quality loss.

  8. Signals of Provenance: Practices & Challenges of Navigating Indicators in AI-Generated Media for Sighted and Blind Individuals

    cs.HC 2025-05 conditional novelty 6.0 of 10

    Both sighted and blind/low-vision users frequently overlook platform AI labels and rely on titles, comments, and other content cues, with blind users further hindered by inaccessible label design.

Pith tools