ZK-WAGON: Imperceptible Watermark for Image Generation Models using ZK-SNARKs

πŸ“… 2025-10-02
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
The proliferation of image generation models exacerbates risks of misinformation, deepfakes, and copyright infringement, while conventional watermarking methods suffer from trade-offs among fidelity, robustness, and deployability. This paper proposes ZK-WAGONβ€”the first imperceptible, verifiable image watermarking framework built on ZK-SNARKs that enables source provenance without access to model weights or prompts. Its core innovation is the Selective-Layer ZK Circuit Construction (SL-ZKCC) method, which supports both GANs and diffusion models while ensuring model-agnosticism and cryptographic verification security; LSB-based steganography enables covert embedding. Experiments demonstrate that ZK-WAGON preserves image quality while achieving fast proof generation, strong resistance to removal attacks, and human-imperceptibility. The framework provides a scalable, zero-trust solution for verifying authenticity and establishing copyright ownership of synthetic media.

Technology Category

Computer Vision: Generative Adversarial Networks (GANs) for VisionMachine Learning: Large Multimodal Models (LMMs)Natural Language Processing: Language Grounding & Multi-modal NLP

Application Category

Security and Privacy: Data transparency and provenanceWeb Mining and Content Analysis: Web data provenance, reliability, and authenticitySearch and Retrieval-Augmented AI: Web search models and ranking
πŸ“ Abstract
As image generation models grow increasingly powerful and accessible, concerns around authenticity, ownership, and misuse of synthetic media have become critical. The ability to generate lifelike images indistinguishable from real ones introduces risks such as misinformation, deepfakes, and intellectual property violations. Traditional watermarking methods either degrade image quality, are easily removed, or require access to confidential model internals - making them unsuitable for secure and scalable deployment. We are the first to introduce ZK-WAGON, a novel system for watermarking image generation models using the Zero-Knowledge Succinct Non Interactive Argument of Knowledge (ZK-SNARKs). Our approach enables verifiable proof of origin without exposing model weights, generation prompts, or any sensitive internal information. We propose Selective Layer ZK-Circuit Creation (SL-ZKCC), a method to selectively convert key layers of an image generation model into a circuit, reducing proof generation time significantly. Generated ZK-SNARK proofs are imperceptibly embedded into a generated image via Least Significant Bit (LSB) steganography. We demonstrate this system on both GAN and Diffusion models, providing a secure, model-agnostic pipeline for trustworthy AI image generation.
Problem

Research questions and friction points this paper is trying to address.

Proving image origin without revealing model secrets
Preventing synthetic media misuse and ownership disputes
Embedding imperceptible watermarks without quality degradation
Innovation

Methods, ideas, or system contributions that make the work stand out.

ZK-SNARKs enable watermarking without exposing model internals
Selective Layer ZK-Circuit Creation reduces proof generation time
LSB steganography embeds imperceptible proofs in generated images
πŸ”Ž Similar Papers
2024-08-11European Conference on Computer VisionCitations: 15
A
Aadarsh Anantha Ramakrishnan
Department of Computer Science and Engineering, National Institute of Technology, Tiruchirappalli, Tiruchirappalli, India
S
Shubham Agarwal
Department of Computer Science and Engineering, National Institute of Technology, Tiruchirappalli, Tiruchirappalli, India
S
Selvanayagam S
Department of Computer Science and Engineering, National Institute of Technology, Tiruchirappalli, Tiruchirappalli, India
Kunwar Singh
Kunwar Singh
CSE Deapartment, NIT Trichy
Cryptology