On the Information-Theoretic Limits of Latent-Space Watermarking Through Pretrained Generators

📅 2026-09-21
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
研究通过预训练生成器进行潜空间水印,使用信息论方法分析了在保持输出分布的同时嵌入水印的能力与限制,并探讨了对抗再生攻击下的鲁棒性。
📝 Abstract
We study latent-space watermarking through a pretrained generator using a prescribed latent-to-output stochastic mapping, called the renderer. A watermark encoder selects the latent input using a message and secret key. For every message and semantic context, the released output must have exactly the desired conditional output distribution. For finite alphabets, we derive rate--key inner and outer bounds and characterize the coding and coordination requirements for realizing watermark communication through the prescribed latent interface. When the target output distribution of the generator uniquely determines the corresponding latent input distribution through the renderer, a strengthened converse yields the capacity region; the same region governs explicit preservation of the pretrained latent distribution. We extend the analysis to general jointly Gaussian models and identify a sufficient statistic of the latent that captures both the watermark-bearing information available at the generated output and the latent coordination required to preserve its target distribution. For the vector Gaussian model, we further characterize the optimal allocation of the secret-key resource across the resulting modes. Finally, we turn to an emerging robustness threat that is particularly natural in generative watermarking: an adversary can regenerate the released sample to obtain a fresh realization of the same underlying content while attenuating or destroying the embedded watermark. We incorporate this robustness axis into our framework and characterize the one-pass compound capacity of the scalar Gaussian model when the semantic context is known to the encoder but hidden from the detector, while the regeneration attack may depend on that context. Extending the analysis to multiple rounds of repeated canonical regeneration, we characterize the resulting watermark-capacity decay.
Problem

Research questions and friction points this paper is trying to address.

latent-space watermarking
pretrained generator
output distribution
adversary
robustness
Innovation

Methods, ideas, or system contributions that make the work stand out.

latent-space watermarking
pretrained generator
stochastic mapping
capacity region
robustness threat
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
J
Jinwan Jeon
Hallym University, CHUNCHEON-SI, GANGWON-DO, South Korea
M
Minju Lee
Hallym University, CHUNCHEON-SI, GANGWON-DO, South Korea
Sung Hoon Lim
Sung Hoon Lim
Hallym University
Information theorycommunication theorymachine learning