Not All Recovered Symbols Are Equal: Reliability-Aware Watermark Verification for Autoregressively Generated Images
Abstract
Recovering verification symbols through retokenization is a key step in verifying watermarks in autoregressively generated images. However, the recovered symbols may differ from those used during generation, especially after image transformations. Importantly, these recovery errors are not uniform: some symbols remain stable, whereas others are more likely to change. Existing watermarking methods, however, typically assign equal decision weight to recovered verification symbols despite their different recovery reliability. This limitation may lead to watermark verification failure. To address this issue, we propose Reliability-Aware Verification (RAV), which predicts symbol survival reliability from recovery-side features, including quantization geometry, posterior uncertainty, consistency, and spatial context, and uses the predicted reliability to weight watermark evidence. By emphasizing reliable symbols and suppressing unreliable ones, RAV reduces the risk of verification failure caused by unreliable recovered evidence. Experiments on WMAR and ClusterMark across three autoregressive image generation models, RAR-XL, TAMING, and LlamaGen GPT-B, show that RAV consistently improves watermark verification under diverse transformations at strict false-positive rates.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.