Guidance Watermarking for Diffusion Models

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Gesny, Enoal, Giboulot, Eva, Furon, Teddy, Chappelier, Vivien
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915988236140544
author Gesny, Enoal
Giboulot, Eva
Furon, Teddy
Chappelier, Vivien
author_facet Gesny, Enoal
Giboulot, Eva
Furon, Teddy
Chappelier, Vivien
contents This paper introduces a novel watermarking method for diffusion models. It is based on guiding the diffusion process using the gradient computed from any off-the-shelf watermark decoder. The gradient computation encompasses different image augmentations, increasing robustness to attacks against which the decoder was not originally robust, without retraining or fine-tuning. Our method effectively convert any \textit{post-hoc} watermarking scheme into an in-generation embedding along the diffusion process. We show that this approach is complementary to watermarking techniques modifying the variational autoencoder at the end of the diffusion process. We validate the methods on different diffusion models and detectors. The watermarking guidance does not significantly alter the generated image for a given seed and prompt, preserving both the diversity and quality of generation.
format Preprint
id arxiv_https___arxiv_org_abs_2509_22126
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Guidance Watermarking for Diffusion Models
Gesny, Enoal
Giboulot, Eva
Furon, Teddy
Chappelier, Vivien
Cryptography and Security
Computer Vision and Pattern Recognition
This paper introduces a novel watermarking method for diffusion models. It is based on guiding the diffusion process using the gradient computed from any off-the-shelf watermark decoder. The gradient computation encompasses different image augmentations, increasing robustness to attacks against which the decoder was not originally robust, without retraining or fine-tuning. Our method effectively convert any \textit{post-hoc} watermarking scheme into an in-generation embedding along the diffusion process. We show that this approach is complementary to watermarking techniques modifying the variational autoencoder at the end of the diffusion process. We validate the methods on different diffusion models and detectors. The watermarking guidance does not significantly alter the generated image for a given seed and prompt, preserving both the diversity and quality of generation.
title Guidance Watermarking for Diffusion Models
topic Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2509.22126