acceptodds
Under review as a conference paper at ICLR 2027

IdentityMark: Source-Side Identity Watermarking for Deepfake Provenance

Abstract

Face-swapping deepfakes can misuse publicly shared portraits to transfer a person’s likeness onto attacker-selected target images, spreading misleading information or damaging the victim’s reputation. Since the resulting deepfake may retain little or none of the source portrait’s pixels or shape, conventional watermarks become ineffective in this scenario. We introduce IdentityMark, a source-side iden- tity watermarking framework that traces such deepfakes to the protected sources, supporting deepfake verification when the target image is beyond the defender’s control. Rather than embedding provenance into image content, IdentityMark en- codes a binary message into the facial identity representation transferred during face swapping. A message-to-identity autoencoder produces a message-bearing identity embedding, while diffusion-based latent optimization moves the source identity em- bedding toward this target while preserving visual fidelity and the original identity. Given a suspicious face-swapped image, the message is decoded directly from its facial identity embedding and compared against the victim’s registered watermarks to verify its authenticity. IdentityMark requires no access to or training through downstream face-swap models, making it agnostic to the face-swapping method. In our evaluated face-swapping setting, IdentityMark achieves 71.66% bit accuracy, compared with approximately 50% for other watermarking methods, consistent with random guessing. These results demonstrate the feasibility of source-side provenance protection for tracing and verifying face-swapping deepfakes.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.