Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Liu, Qingyu, Zhang, Yitao, Ba, Zhongjie, Shuai, Chao, Cheng, Peng, Zheng, Tianhang, Wang, Zhibo
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915720461287424
author Liu, Qingyu
Zhang, Yitao
Ba, Zhongjie
Shuai, Chao
Cheng, Peng
Zheng, Tianhang
Wang, Zhibo
author_facet Liu, Qingyu
Zhang, Yitao
Ba, Zhongjie
Shuai, Chao
Cheng, Peng
Zheng, Tianhang
Wang, Zhibo
contents Protecting the copyright of user-generated AI images is an emerging challenge as AIGC becomes pervasive in creative workflows. Existing watermarking methods (1) remain vulnerable to real-world adversarial threats, often forced to trade off between defenses against spoofing and removal attacks; and (2) cannot support semantic-level tamper localization. We introduce PAI, a training-free inherent watermarking framework for AIGC copyright protection, plug-and-play with diffusion-based AIGC services. PAI simultaneously provides three key functionalities: robust ownership verification, attack detection, and semantic-level tampering localization. Unlike existing inherent watermark methods that only embed watermarks at noise initialization of diffusion models, we design a novel key-conditioned deflection mechanism that subtly steers the denoising trajectory according to the user key. Such trajectory-level coupling further strengthens the semantic entanglement of identity and content, thereby further enhancing robustness against real-world threats. Moreover, we also provide a theoretical analysis proving that only the valid key can pass verification. Experiments across 12 attack methods show that PAI achieves 98.43\% verification accuracy, improving over SOTA methods by 37.25\% on average, and retains strong tampering localization performance even against advanced AIGC edits. Our code is available at https://github.com/QingyuLiu/PAI.
format Preprint
id arxiv_https___arxiv_org_abs_2601_06639
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection
Liu, Qingyu
Zhang, Yitao
Ba, Zhongjie
Shuai, Chao
Cheng, Peng
Zheng, Tianhang
Wang, Zhibo
Cryptography and Security
Artificial Intelligence
Protecting the copyright of user-generated AI images is an emerging challenge as AIGC becomes pervasive in creative workflows. Existing watermarking methods (1) remain vulnerable to real-world adversarial threats, often forced to trade off between defenses against spoofing and removal attacks; and (2) cannot support semantic-level tamper localization. We introduce PAI, a training-free inherent watermarking framework for AIGC copyright protection, plug-and-play with diffusion-based AIGC services. PAI simultaneously provides three key functionalities: robust ownership verification, attack detection, and semantic-level tampering localization. Unlike existing inherent watermark methods that only embed watermarks at noise initialization of diffusion models, we design a novel key-conditioned deflection mechanism that subtly steers the denoising trajectory according to the user key. Such trajectory-level coupling further strengthens the semantic entanglement of identity and content, thereby further enhancing robustness against real-world threats. Moreover, we also provide a theoretical analysis proving that only the valid key can pass verification. Experiments across 12 attack methods show that PAI achieves 98.43\% verification accuracy, improving over SOTA methods by 37.25\% on average, and retains strong tampering localization performance even against advanced AIGC edits. Our code is available at https://github.com/QingyuLiu/PAI.
title Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2601.06639