GaussMarker: Robust Dual-Domain Watermark for Diffusion Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Kecen, Huang, Zhicong, Hou, Xinwen, Hong, Cheng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909647653306368
author Li, Kecen
Huang, Zhicong
Hou, Xinwen
Hong, Cheng
author_facet Li, Kecen
Huang, Zhicong
Hou, Xinwen
Hong, Cheng
contents As Diffusion Models (DM) generate increasingly realistic images, related issues such as copyright and misuse have become a growing concern. Watermarking is one of the promising solutions. Existing methods inject the watermark into the single-domain of initial Gaussian noise for generation, which suffers from unsatisfactory robustness. This paper presents the first dual-domain DM watermarking approach using a pipelined injector to consistently embed watermarks in both the spatial and frequency domains. To further boost robustness against certain image manipulations and advanced attacks, we introduce a model-independent learnable Gaussian Noise Restorer (GNR) to refine Gaussian noise extracted from manipulated images and enhance detection robustness by integrating the detection scores of both watermarks. GaussMarker efficiently achieves state-of-the-art performance under eight image distortions and four advanced attacks across three versions of Stable Diffusion with better recall and lower false positive rates, as preferred in real applications.
format Preprint
id arxiv_https___arxiv_org_abs_2506_11444
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle GaussMarker: Robust Dual-Domain Watermark for Diffusion Models
Li, Kecen
Huang, Zhicong
Hou, Xinwen
Hong, Cheng
Cryptography and Security
Computer Vision and Pattern Recognition
As Diffusion Models (DM) generate increasingly realistic images, related issues such as copyright and misuse have become a growing concern. Watermarking is one of the promising solutions. Existing methods inject the watermark into the single-domain of initial Gaussian noise for generation, which suffers from unsatisfactory robustness. This paper presents the first dual-domain DM watermarking approach using a pipelined injector to consistently embed watermarks in both the spatial and frequency domains. To further boost robustness against certain image manipulations and advanced attacks, we introduce a model-independent learnable Gaussian Noise Restorer (GNR) to refine Gaussian noise extracted from manipulated images and enhance detection robustness by integrating the detection scores of both watermarks. GaussMarker efficiently achieves state-of-the-art performance under eight image distortions and four advanced attacks across three versions of Stable Diffusion with better recall and lower false positive rates, as preferred in real applications.
title GaussMarker: Robust Dual-Domain Watermark for Diffusion Models
topic Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2506.11444