acceptodds
Under review as a conference paper at ICLR 2027

SHield: Watermarking 4D Gaussian Splatting via Spherical Harmonic Coefficient Perturbation

Abstract

4D Gaussian Splatting (4DGS) models are computationally expensive to train but distributed as easily copied parameter files. Existing watermarks protect these assets by fine-tuning the scene against a neural decoder to extract bit strings from rendered video, a heavy process vulnerable to the temporal dynamics of dynamic scenes. However, if the threat model targets the redistributed file itself, verification can be vastly simplified. Because the canonical Spherical-Harmonic (SH) coefficients of 4DGS are time- and view-invariant, parameter-space perturbations can be recovered via deterministic arithmetic. We propose **SHield**, the first non-blind, decoder-free watermarking approach that natively embeds full-resolution RGB images into 4DGS files. SHield tiles a zero-mean payload across the SH coefficients of a key-selected Gaussian subset, applying a brief anchored optimization to preserve visual fidelity. To verify ownership, it geometrically re-associates the key using canonical Gaussian centres to survive file tampering and recovers the payload in closed form. Across 30 scenes (D-NeRF, HyperNeRF, DyNeRF), SHield guarantees near-perfect payload recovery (Pearson ) on all 150 tested models with a mean rendering penalty of dB. Held-out evaluation yields perfect detection on 400 true trials and zero false positives across wrong-subset null trials. We also strictly bound the method's robustness: SHield survives INT8 quantization and opacity pruning for the image payload, and on aggressive SH-degree-1 truncation bit payloads are still decodable.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.