Watermarking Autoregressive Image Generation
Fuente:
arXiv
Guardado en:
| Autores principales: | , , , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866914109205774336 |
|---|---|
| author | Jovanović, Nikola Labiad, Ismail Souček, Tomáš Vechev, Martin Fernandez, Pierre |
| author_facet | Jovanović, Nikola Labiad, Ismail Souček, Tomáš Vechev, Martin Fernandez, Pierre |
| contents | Watermarking the outputs of generative models has emerged as a promising approach for tracking their provenance. Despite significant interest in autoregressive image generation models and their potential for misuse, no prior work has attempted to watermark their outputs at the token level. In this work, we present the first such approach by adapting language model watermarking techniques to this setting. We identify a key challenge: the lack of reverse cycle-consistency (RCC), wherein re-tokenizing generated image tokens significantly alters the token sequence, effectively erasing the watermark. To address this and to make our method robust to common image transformations, neural compression, and removal attacks, we introduce (i) a custom tokenizer-detokenizer finetuning procedure that improves RCC, and (ii) a complementary watermark synchronization layer. As our experiments demonstrate, our approach enables reliable and robust watermark detection with theoretically grounded p-values. Code and models are available at https://github.com/facebookresearch/wmar. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2506_16349 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Watermarking Autoregressive Image Generation Jovanović, Nikola Labiad, Ismail Souček, Tomáš Vechev, Martin Fernandez, Pierre Machine Learning Artificial Intelligence Cryptography and Security Computer Vision and Pattern Recognition Watermarking the outputs of generative models has emerged as a promising approach for tracking their provenance. Despite significant interest in autoregressive image generation models and their potential for misuse, no prior work has attempted to watermark their outputs at the token level. In this work, we present the first such approach by adapting language model watermarking techniques to this setting. We identify a key challenge: the lack of reverse cycle-consistency (RCC), wherein re-tokenizing generated image tokens significantly alters the token sequence, effectively erasing the watermark. To address this and to make our method robust to common image transformations, neural compression, and removal attacks, we introduce (i) a custom tokenizer-detokenizer finetuning procedure that improves RCC, and (ii) a complementary watermark synchronization layer. As our experiments demonstrate, our approach enables reliable and robust watermark detection with theoretically grounded p-values. Code and models are available at https://github.com/facebookresearch/wmar. |
| title | Watermarking Autoregressive Image Generation |
| topic | Machine Learning Artificial Intelligence Cryptography and Security Computer Vision and Pattern Recognition |
| url | https://arxiv.org/abs/2506.16349 |