Fast, Secure, and High-Capacity Image Watermarking with Autoencoded Text Vectors

📅 2025-10-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Existing image watermarking methods treat payloads as semantically agnostic bitstreams, limiting capacity and precluding embedding of human-interpretable, high-level semantic information. Method: We propose a novel semantic watermarking paradigm: (i) compress full natural-language sentences into 256-dimensional unit-norm latent vectors via a lightweight text autoencoder; (ii) fine-tune a watermarking model for robust embedding; and (iii) enforce security via a secret, invertible rotation transformation. Contributions/Results: Our approach breaks the conventional 256-bit capacity ceiling, enabling sentence-level semantic steganography and millisecond-scale real-time decoding. A statistically calibrated scoring mechanism supports AI-generated content provenance tracing and tampering attribution. Evaluated on multiple benchmarks, it substantially outperforms state-of-the-art methods—achieving superior BLEU-4 and Exact Match scores, and ROC AUC of 0.97–0.99—while maintaining strong robustness against geometric and value-domain attacks and offering full interpretability.

Technology Category

Natural Language Processing: Sentence-level Semantics, Textual Inference, etc.Machine Learning: Large Multimodal Models (LMMs)Computer Vision: Adversarial Attacks & Robustness

Application Category

Semantics and Knowledge: Methods to enhance, augment, integrate or synergize semantic models such as knowledge graphs and LLMsSearch and Retrieval-Augmented AI: Large language models for searchSecurity and Privacy: Data transparency and provenance
📝 Abstract
Most image watermarking systems focus on robustness, capacity, and imperceptibility while treating the embedded payload as meaningless bits. This bit-centric view imposes a hard ceiling on capacity and prevents watermarks from carrying useful information. We propose LatentSeal, which reframes watermarking as semantic communication: a lightweight text autoencoder maps full-sentence messages into a compact 256-dimensional unit-norm latent vector, which is robustly embedded by a finetuned watermark model and secured through a secret, invertible rotation. The resulting system hides full-sentence messages, decodes in real time, and survives valuemetric and geometric attacks. It surpasses prior state of the art in BLEU-4 and Exact Match on several benchmarks, while breaking through the long-standing 256-bit payload ceiling. It also introduces a statistically calibrated score that yields a ROC AUC score of 0.97-0.99, and practical operating points for deployment. By shifting from bit payloads to semantic latent vectors, LatentSeal enables watermarking that is not only robust and high-capacity, but also secure and interpretable, providing a concrete path toward provenance, tamper explanation, and trustworthy AI governance. Models, training and inference code, and data splits will be available upon publication.
Problem

Research questions and friction points this paper is trying to address.

Developing high-capacity watermarking using semantic latent vectors instead of bits
Enabling secure embedding of full-sentence messages resistant to attacks
Breaking the 256-bit payload limit while maintaining robustness and interpretability
Innovation

Methods, ideas, or system contributions that make the work stand out.

Autoencoder maps text to compact latent vectors
Fine-tuned watermark model embeds vectors robustly
Secret invertible rotation secures the watermarking process
🔎 Similar Papers
2024-07-26International Workshop on Information Forensics and SecurityCitations: 5
2024-08-11European Conference on Computer VisionCitations: 15
G
Gautier Evennou
IRISA, Univ. Rennes, CNRS
V
Vivien Chappelier
Imatag
E
Ewa Kijak
IRISA, Univ. Rennes, CNRS