CSGuard: Toward Forgery-Resistant Watermarking in Diffusion Models via Compressed Sensing Constraint

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lai, Jiewei, Zhang, Lan, Tang, Chen, Sun, Pengcheng, Zhang, Zhaopeng, Wang, Yunhao, Jin, Hui
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914526345035776
author Lai, Jiewei
Zhang, Lan
Tang, Chen
Sun, Pengcheng
Zhang, Zhaopeng
Wang, Yunhao
Jin, Hui
author_facet Lai, Jiewei
Zhang, Lan
Tang, Chen
Sun, Pengcheng
Zhang, Zhaopeng
Wang, Yunhao
Jin, Hui
contents Latent-based diffusion model watermarking embeds watermarks into generated images' latent space to enable content attribution, offering a training-free solution for intellectual property protection and digital forensics. However, these methods exhibit a critical vulnerability to the forgery attack, attackers can extract the watermark by inverting the watermarked image and re-generating it with an arbitrary prompt, thereby enabling false attribution on malicious content. In this paper, we propose the CSGuard, the first forgery-resistant watermarking schema that leverages compressed sensing to bind the watermarked image generation and verification to a secret matrix. This ensures that only users possessing the secret matrix can correctly embed or verify the image watermark, prevents the illegal users from forgery without compromising generation quality and watermark integrity. Experimental results demonstrate that CSGuard achieves strong forgery resistance, reduces the attack success rate from 100.0\% to 28.12\%, and achieve 100\% detection rate on benign watermarked images without compromising watermarking effectiveness.
format Preprint
id arxiv_https___arxiv_org_abs_2605_01479
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle CSGuard: Toward Forgery-Resistant Watermarking in Diffusion Models via Compressed Sensing Constraint
Lai, Jiewei
Zhang, Lan
Tang, Chen
Sun, Pengcheng
Zhang, Zhaopeng
Wang, Yunhao
Jin, Hui
Computer Vision and Pattern Recognition
Latent-based diffusion model watermarking embeds watermarks into generated images' latent space to enable content attribution, offering a training-free solution for intellectual property protection and digital forensics. However, these methods exhibit a critical vulnerability to the forgery attack, attackers can extract the watermark by inverting the watermarked image and re-generating it with an arbitrary prompt, thereby enabling false attribution on malicious content. In this paper, we propose the CSGuard, the first forgery-resistant watermarking schema that leverages compressed sensing to bind the watermarked image generation and verification to a secret matrix. This ensures that only users possessing the secret matrix can correctly embed or verify the image watermark, prevents the illegal users from forgery without compromising generation quality and watermark integrity. Experimental results demonstrate that CSGuard achieves strong forgery resistance, reduces the attack success rate from 100.0\% to 28.12\%, and achieve 100\% detection rate on benign watermarked images without compromising watermarking effectiveness.
title CSGuard: Toward Forgery-Resistant Watermarking in Diffusion Models via Compressed Sensing Constraint
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2605.01479