🤖 AI Summary
This work addresses the vulnerability of existing inversion-based diffusion watermarking methods to composite lossy post-processing involving rotation, which disrupts spatial correspondence and causes watermark failure. The study is the first to identify and exploit a “rotation synchronization” property in latent space—where the rotation of an image aligns precisely with the rotation angle of its initial latent variable—and proposes a training-free, robust watermarking scheme. By embedding a synchronization anchor at the center of the latent space, the method enables accurate estimation and correction of rotation angles. This approach substantially improves bit accuracy under rotation and composite attacks while preserving near-original image quality.
📝 Abstract
Inversion-based watermarking embeds watermark payloads directly into the generative process, avoiding a separate post-hoc image-domain embedding stage while preserving the native visual fidelity of synthesized images. However, existing methods remain vulnerable to compound lossy post-processing, particularly when rotation is involved, as it disrupts the spatial correspondence required for latent-space decoding. To overcome this limitation, we introduce AnchorMark, a training-free, robust inversion-based watermarking. We uncover a latent-space property termed Rotation Synchrony: image-domain rotations and their counterparts in the recovered initial latent share the same angle. Building on this property, AnchorMark embeds a synchronization anchor in the central region of the initial latent, enabling accurate estimation and correction of the rotation angle during extraction. Experiments show that AnchorMark substantially improves bit accuracy under rotation and combined attacks, with limited impact on image quality.