HMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Kexin, Ding, Guozhen, Grishchenko, Ilya, Lie, David
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915644531802112
author Li, Kexin
Ding, Guozhen
Grishchenko, Ilya
Lie, David
author_facet Li, Kexin
Ding, Guozhen
Grishchenko, Ilya
Lie, David
contents Modern generative diffusion models rely on vast training datasets, often including images with uncertain ownership or usage rights. Radioactive watermarks -- marks that transfer to a model's outputs -- can help detect when such unauthorized data has been used for training. Moreover, aside from being radioactive, an effective watermark for protecting images from unauthorized training also needs to meet other existing requirements, such as imperceptibility, robustness, and multi-bit capacity. To overcome these challenges, we propose HMARK, a novel multi-bit watermarking scheme, which encodes ownership information as secret bits in the semantic-latent space (h-space) for image diffusion models. By leveraging the interpretability and semantic significance of h-space, ensuring that watermark signals correspond to meaningful semantic attributes, the watermarks embedded by HMARK exhibit radioactivity, robustness to distortions, and minimal impact on perceptual quality. Experimental results demonstrate that HMARK achieves 98.57% watermark detection accuracy, 95.07% bit-level recovery accuracy, 100% recall rate, and 1.0 AUC on images produced by the downstream adversarial model finetuned with LoRA on watermarked data across various types of distortions.
format Preprint
id arxiv_https___arxiv_org_abs_2512_00094
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle HMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models
Li, Kexin
Ding, Guozhen
Grishchenko, Ilya
Lie, David
Cryptography and Security
Computer Vision and Pattern Recognition
Modern generative diffusion models rely on vast training datasets, often including images with uncertain ownership or usage rights. Radioactive watermarks -- marks that transfer to a model's outputs -- can help detect when such unauthorized data has been used for training. Moreover, aside from being radioactive, an effective watermark for protecting images from unauthorized training also needs to meet other existing requirements, such as imperceptibility, robustness, and multi-bit capacity. To overcome these challenges, we propose HMARK, a novel multi-bit watermarking scheme, which encodes ownership information as secret bits in the semantic-latent space (h-space) for image diffusion models. By leveraging the interpretability and semantic significance of h-space, ensuring that watermark signals correspond to meaningful semantic attributes, the watermarks embedded by HMARK exhibit radioactivity, robustness to distortions, and minimal impact on perceptual quality. Experimental results demonstrate that HMARK achieves 98.57% watermark detection accuracy, 95.07% bit-level recovery accuracy, 100% recall rate, and 1.0 AUC on images produced by the downstream adversarial model finetuned with LoRA on watermarked data across various types of distortions.
title HMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models
topic Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2512.00094