acceptodds
Under review as a conference paper at ICLR 2027

IRIS: Visual-Semantic Binding for Diffusion Image Watermarking

Abstract

In-generation watermarking provides a promising approach to tracing diffusion-generated images, but recent work shows such watermarks can be transplanted onto arbitrary images because they are agnostic to the visual content being watermarked. Prior content-aware methods bind the watermark only to prompt-level semantics, leaving it loosely coupled to the visual content it watermarks. We present IRIS, a training-free in-generation watermarking framework that binds each watermark to the visual semantics of the generated image. This introduces two challenges: (1) deriving the watermark requires the visual semantics of the generated image, yet embedding that watermark during generation may itself alter those semantics, creating a circular dependency, and (2) verification should be sensitive to semantic changes while resilient to common image distortions. To address the first challenge, IRIS derives the watermark from the visual semantics of a preview. It embeds the watermark as a small perturbation in the Fourier domain of the latent only during the final few sampling steps, thereby preserving those semantics. To address the second challenge, IRIS constructs distortion-robust semantic codes from augmented visual representations. At detection, IRIS derives the expected watermark from the query image and verifies it against the inverted latents. Extensive experiments show that IRIS reduces the mean black-box forgery attack success rate from over 96% for content-agnostic methods and 11–61% for prior content-aware methods to 2.1%, while keeping high detectability and generalizing to SD3.5 and FLUX.2.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.