RepMark: Representation-Stable Radioactive Latent Watermarking for Diffusion Models
Abstract
Watermarks for image provenance do not necessarily survive downstream model training, limiting their use for tracing unauthorized training data. We introduce RepMark, a radioactive latent watermark designed to remain recoverable across representation changes and to propagate into diffusion models. RepMark maps a multibit owner message to a bounded displacement in shared writing coordinates, creating a consistent signal across protected images. A LoRA-adapted decoder writes the signal, while a private LoRA-adapted encoder and a proxy-VAE training path support message extraction after representation changes. The resulting interface supports post-processing of completed images, in-processing through compatible VAE replacement, and pre-processing for training-data tracing. In the last setting, the watermark is inherited through training, eliminating an additional online writing step at deployment and enabling black-box verification from novel model outputs. Across PixArt fine-tuning and LightningDiT training from scratch, RepMark achieves – per-image presence AUROC in the evaluated settings. Multi-image aggregation further recovers the registered owner message, including after protected training data are encoded by an external SD3.5 VAE, while maintaining image quality and limited separability under specified public-representation tests.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.