OptMark: Robust Multi-bit Diffusion Watermarking via Inference Time Optimization
By: Jiazheng Xing , Hai Ci , Hongbin Xu and more
Potential Business Impact:
Marks AI art so you know who made it.
Watermarking diffusion-generated images is crucial for copyright protection and user tracking. However, current diffusion watermarking methods face significant limitations: zero-bit watermarking systems lack the capacity for large-scale user tracking, while multi-bit methods are highly sensitive to certain image transformations or generative attacks, resulting in a lack of comprehensive robustness. In this paper, we propose OptMark, an optimization-based approach that embeds a robust multi-bit watermark into the intermediate latents of the diffusion denoising process. OptMark strategically inserts a structural watermark early to resist generative attacks and a detail watermark late to withstand image transformations, with tailored regularization terms to preserve image quality and ensure imperceptibility. To address the challenge of memory consumption growing linearly with the number of denoising steps during optimization, OptMark incorporates adjoint gradient methods, reducing memory usage from O(N) to O(1). Experimental results demonstrate that OptMark achieves invisible multi-bit watermarking while ensuring robust resilience against valuemetric transformations, geometric transformations, editing, and regeneration attacks.
Similar Papers
Diffusion-Based Image Editing: An Unforeseen Adversary to Robust Invisible Watermarks
Cryptography and Security
Makes hidden messages in pictures disappear.
On the Information-Theoretic Fragility of Robust Watermarking under Diffusion Editing
Cryptography and Security
Breaks hidden codes in pictures using AI.
HMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models
Cryptography and Security
Marks AI art to show if it used stolen pictures.