SLICE: Semantic Latent Injection via Compartmentalized Embedding for Image Watermarking

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gao, Zheng, Yang, Yifan, Li, Xiaoyu, Feng, Xiaoyan, Fan, Haoran, Song, Yang, Jiang, Jiaojiao
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911512122097664
author Gao, Zheng
Yang, Yifan
Li, Xiaoyu
Feng, Xiaoyan
Fan, Haoran
Song, Yang
Jiang, Jiaojiao
author_facet Gao, Zheng
Yang, Yifan
Li, Xiaoyu
Feng, Xiaoyan
Fan, Haoran
Song, Yang
Jiang, Jiaojiao
contents Watermarking the initial noise of diffusion models has emerged as a promising approach for image provenance, but content-independent noise patterns can be forged via inversion and regeneration attacks. Recent semantic-aware watermarking methods improve robustness by conditioning verification on image semantics. However, their reliance on a single global semantic binding makes them vulnerable to localized but globally coherent semantic edits. To address this limitation and provide a trustworthy semantic-aware watermark, we propose $\underline{\textbf{S}}$emantic $\underline{\textbf{L}}$atent $\underline{\textbf{I}}$njection via $\underline{\textbf{C}}$ompartmentalized $\underline{\textbf{E}}$mbedding ($\textbf{SLICE}$). Our framework decouples image semantics into four semantic factors (subject, environment, action, and detail) and precisely anchors them to distinct regions in the initial Gaussian noise. This fine-grained semantic binding enables advanced watermark verification where semantic tampering is detectable and localizable. We theoretically justify why SLICE enables robust and reliable tamper localization and provides statistical guarantees on false-accept rates. Experimental results demonstrate that SLICE significantly outperforms existing baselines against advanced semantic-guided regeneration attacks, substantially reducing attack success while preserving image quality and semantic fidelity. Overall, SLICE offers a practical, training-free provenance solution that is both fine-grained in diagnosis and robust to realistic adversarial manipulations.
format Preprint
id arxiv_https___arxiv_org_abs_2603_12749
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle SLICE: Semantic Latent Injection via Compartmentalized Embedding for Image Watermarking
Gao, Zheng
Yang, Yifan
Li, Xiaoyu
Feng, Xiaoyan
Fan, Haoran
Song, Yang
Jiang, Jiaojiao
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
Watermarking the initial noise of diffusion models has emerged as a promising approach for image provenance, but content-independent noise patterns can be forged via inversion and regeneration attacks. Recent semantic-aware watermarking methods improve robustness by conditioning verification on image semantics. However, their reliance on a single global semantic binding makes them vulnerable to localized but globally coherent semantic edits. To address this limitation and provide a trustworthy semantic-aware watermark, we propose $\underline{\textbf{S}}$emantic $\underline{\textbf{L}}$atent $\underline{\textbf{I}}$njection via $\underline{\textbf{C}}$ompartmentalized $\underline{\textbf{E}}$mbedding ($\textbf{SLICE}$). Our framework decouples image semantics into four semantic factors (subject, environment, action, and detail) and precisely anchors them to distinct regions in the initial Gaussian noise. This fine-grained semantic binding enables advanced watermark verification where semantic tampering is detectable and localizable. We theoretically justify why SLICE enables robust and reliable tamper localization and provides statistical guarantees on false-accept rates. Experimental results demonstrate that SLICE significantly outperforms existing baselines against advanced semantic-guided regeneration attacks, substantially reducing attack success while preserving image quality and semantic fidelity. Overall, SLICE offers a practical, training-free provenance solution that is both fine-grained in diagnosis and robust to realistic adversarial manipulations.
title SLICE: Semantic Latent Injection via Compartmentalized Embedding for Image Watermarking
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2603.12749