C-TQIM: Cost-Aware Terminal Quantization for Inversion-Free Diffusion Watermarking
Abstract
Image watermarks must survive image processing while preserving the intended output. We study this trade-off with frozen generator and variational autoencoder (VAE) weights, no additional neural watermark decoder, and detection through one VAE encoding without diffusion inversion. We propose C-TQIM, a cost-aware terminal quantization index modulation (QIM) method that embeds a fixed keyed pilot between sampling and VAE decoding. Offline calibration estimates the RGB distortion cost and bias-preserving mean squared error of each candidate discrete cosine transform (DCT) direction under the fixed Identity-calibrated reader used at deployment. A joint criterion selects 144 carriers for nearest-lattice embedding, and an analytic detector aggregates their affine-corrected, pilot-aligned scores. On Stable Diffusion 3.5 Medium, with 1,000 threshold-calibration hosts and 4,000 matched test hosts, C-TQIM achieves a macro AUC of 0.9946 and macro true-positive rate (TPR) of 95.40% across 13 conditions. The maximum observed false-positive rate (FPR) is 0.775%, with paired PSNR of 33.36 dB and LPIPS of 0.0212. In a separate 800-host comparison matched by development PSNR, joint selection improves macro TPR over cost-only selection by 4.45 percentage points (95% paired interval: 3.85–5.04). C-TQIM provides a directly readable fixed-key presence channel without changing the sampling process or training a watermark-specific neural decoder.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.