English

SAT-LDM: Provably Generalizable Image Watermarking for Latent Diffusion Models with Self-Augmented Training

Machine Learning 2025-02-18 v2 Cryptography and Security Computer Vision and Pattern Recognition

Abstract

The rapid proliferation of AI-generated images necessitates effective watermarking techniques to protect intellectual property and detect fraudulent content. While existing training-based watermarking methods show promise, they often struggle with generalizing across diverse prompts and tend to introduce visible artifacts. To this end, we propose a novel, provably generalizable image watermarking approach for Latent Diffusion Models, termed Self-Augmented Training (SAT-LDM). Our method aligns the training and testing phases through a free generation distribution, thereby enhancing the watermarking module's generalization capabilities. We theoretically consolidate SAT-LDM by proving that the free generation distribution contributes to its tight generalization bound, without the need for additional data collection. Extensive experiments show that SAT-LDM not only achieves robust watermarking but also significantly improves the quality of watermarked images across a wide range of prompts. Moreover, our experimental analyses confirm the strong generalization abilities of SAT-LDM. We hope that our method provides a practical and efficient solution for securing high-fidelity AI-generated content.

Keywords

Cite

@article{arxiv.2501.00463,
  title  = {SAT-LDM: Provably Generalizable Image Watermarking for Latent Diffusion Models with Self-Augmented Training},
  author = {Lu Zhang and Liang Zeng},
  journal= {arXiv preprint arXiv:2501.00463},
  year   = {2025}
}

Comments

21 pages, 7 figures

R2 v1 2026-06-28T20:53:23.443Z