acceptodds
Under review as a conference paper at ICLR 2027

SRW: FROM DISCRETE WATERMARK IDENTIFICATION TO SEMANTIC PROVENANCE RETRIEVAL

Abstract

Watermarking embeds recoverable source information in AI-generated images to support attribution and auditing after dissemination. Compression, cropping, resizing, and editing can damage this signal, while incomplete provenance records create a second obstacle: recovering a discrete identifier does not by itself retrieve a semantically equivalent source description. We introduce SRW, which reframes watermark identification as semantic provenance retrieval. A provenance payload is source metadata intentionally embedded in the image and may differ from the prompt controlling visible content. SRW selects informative payload tokens, injects their continuous representation into diffusion latents, and learns to recover it from distorted images for cosine-ranked search with calibrated rejection. In the recorded attack sweep, retrieval accuracy is 94% after JPEG quality 50, 95% after 0.5× resizing, and 94% after a 20% crop. In a separate evaluation excluding the exact source text, Recall@1 reaches 93% for paraphrases and 82% for hard semantic neighbors. Payload-shuffling summaries further support recovery of the embedded payload rather than visible content alone. Bank-size diagnostics give 98% Top-1 at 1K candidates and 92% at 10K. These results support a semantic retrieval interface beyond discrete identity lookup, with strong impulse noise, image fidelity, and joint distortion–source-absence evaluation remaining limitations.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.