REVIEW 19 cited by
Tree-Ring Watermarks: Fingerprints for Diffusion Images that are Invisible and Robust
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Watermarking the outputs of generative models is a crucial technique for tracing copyright and preventing potential harm from AI-generated content. In this paper, we introduce a novel technique called Tree-Ring Watermarking that robustly fingerprints diffusion model outputs. Unlike existing methods that perform post-hoc modifications to images after sampling, Tree-Ring Watermarking subtly influences the entire sampling process, resulting in a model fingerprint that is invisible to humans. The watermark embeds a pattern into the initial noise vector used for sampling. These patterns are structured in Fourier space so that they are invariant to convolutions, crops, dilations, flips, and rotations. After image generation, the watermark signal is detected by inverting the diffusion process to retrieve the noise vector, which is then checked for the embedded signal. We demonstrate that this technique can be easily applied to arbitrary diffusion models, including text-conditioned Stable Diffusion, as a plug-in with negligible loss in FID. Our watermark is semantically hidden in the image space and is far more robust than watermarking alternatives that are currently deployed. Code is available at https://github.com/YuxinWenRick/tree-ring-watermark.
Forward citations
Cited by 19 Pith papers
-
LEGO: LoRA-Enabled Generator-Oriented Framework for Synthetic Image Detection
LEGO uses multiple generator-specific LoRA modules modulated by an MLP and fused with attention to detect synthetic images, achieving better performance than prior methods while using under 10% of the training data.
-
Watermarking Large Language Model-based Time Series Forecasting
Waltz embeds watermarks into LLM-based time series forecasts by nudging a few patch embeddings toward 'cold' LLM tokens, and detects them with a z-score test.
-
AnchorMark: Robust Diffusion Watermarking via Latent-Space Rotation Synchrony
Image rotation is shown to rotate the recovered latent by the same angle, and a central phase anchor exploits this to estimate and undo rotation before decoding the watermark.
-
FARI: Robust One-Step Inversion for Watermarking in Diffusion Models
One-step adversarially LoRA-tuned inversion exploits low-curvature reverse trajectories to beat 50-step DDIM on watermark robustness after ~20 minutes of fine-tuning.
-
DNA: Dual-stage Native Attribution for Generated Image Source Tracing
A training-free two-stage framework (family-level VAE screening + backbone-level native-prediction scoring) traces generated images to specific within-family model variants at 89.11% end-to-end accuracy on a new open-...
-
Who Gets Flagged? The Pluralistic Evaluation Gap in AI Content Watermarking
Major watermarking benchmarks omit cross-lingual, cultural, and demographic reporting, creating a pluralistic evaluation gap that current governance mandates ignore.
-
ShapeMark: Robust and Diversity-Preserving Watermarking for Diffusion Models
ShapeMark embeds watermark bits as block-level permutations of a key-derived Gaussian noise latent, achieving higher robustness and diversity than prior noise-as-watermark methods.
-
IConMark: Robust Interpretable Concept-Based Watermark For AI Images
IConMark adds preselected, human-readable objects to AI images via prompt engineering and detects them with a vision-language model, achieving higher AUROC than noise-based watermarks on tested augmentations.
-
A Watermark for Auto-Regressive Image Generation Models
Clustering visual tokens into equivalence classes lets a distortion-free reweight watermark survive the retokenization step in auto-regressive image generation.
-
Autoregressive Images Watermarking through Lexical Biasing: An Approach Resistant to Regeneration Attack
LBW embeds watermarks into autoregressive image token maps by biasing token sampling toward a secret green list and detects them with a z-test on green-token counts.
-
MUSE: Model-Agnostic Tabular Watermarking via Multi-Sample Selection
MUSE embeds a watermark in tabular synthetic data by selecting, among several generated candidate rows, the one with the highest keyed hash score, enabling detection without model inversion.
-
Learning Single Index Models with Diffusion Priors
A method called SIM-DMIS recovers signals from single index model measurements in about 150 neural function evaluations by starting diffusion model inversion at an intermediate time matched to the measurement noise level.
-
Signals of Provenance: Practices & Challenges of Navigating Indicators in AI-Generated Media for Sighted and Blind Individuals
Both sighted and blind/low-vision users frequently overlook platform AI labels and rely on titles, comments, and other content cues, with blind users further hindered by inaccessible label design.
-
Training-Free Watermarking for Autoregressive Image Generation
IndexMark watermarks images from autoregressive models by replacing similar codebook tokens with green tokens, then detecting the green-token rate after reconstruction.
-
BiSLW: Bi-Spectral Latent Watermarking for Generative Diffusion Models
Learned dual-band DCT watermarking of diffusion latents improves PSNR by ~3 dB over prior latent methods while keeping near-perfect bit accuracy under regeneration and distortions.
-
Position: AI/ML Deepfake Research is Misaligned with AI-Generated Non-Consensual Intimate Imagery (AIG-NCII)
The dominant real-world use of generative-image abuse is non-consensual intimate imagery, yet the AI/ML research field focuses almost exclusively on viewer deception.
-
ArtifactGen: Benchmarking WGAN-GP vs Diffusion for Label-Aware EEG Artifact Synthesis
A WGAN-GP achieves closer spectral alignment and lower MMD than a diffusion model for EEG artifact synthesis, but class-conditional recovery is weak for both.
-
Temperature Matters: Enhancing Watermark Robustness Against Paraphrasing Attacks
A watermark that seeds each token's sampling temperature from a hash of the previous h tokens is claimed to beat the Aaronson watermark under a 30% BERT paraphrase attack, based on a single ROC curve without error bars.
-
TRACE: Trajectory-Constrained Concept Erasure in Diffusion Models
TRACE combines a closed-form cross-attention nullification with a late-timestep fine-tuning loss to erase concepts from diffusion models, claiming better erasure and fidelity than published baselines.
Discussion (0). Sign in to comment.