FreqWak: Lightweight Inversion-Free Frequency-Domain Watermarking For Time Series Data
Abstract
Synthetic time series produced by diffusion models make it possible to share privacy-sensitive datasets, such as patients' functional MRI records. Important criteria for synthetic data include high data utility and traceability for verifying the data source. Existing state-of-the-art methods (e.g., TimeWak) rely on costly diffusion inversion, incurring approximation errors and yielding low bit accuracy (55%–96%), and suffering from low detection efficiency. We propose FreqWak, to the best of our knowledge, the first lightweight frequency-domain watermarking framework that eliminates diffusion inversion and achieves over 99.9% bit accuracy under our evaluation settings. FreqWak embeds watermarks by modulating the phase of the residual frequency band in the post-sampling time series. Detection requires only a single rFFT, enabling highly accurate and inversion-free verification without modifying the diffusion training process. We extensively evaluate FreqWak across five datasets and multiple baselines, in terms of its impact on synthetic data quality, watermark detectability, and robustness under various post-editing attacks. Our results show that FreqWak achieves nearly 100% bit accuracy across all tested lengths, with detection 19–1,256× faster than TimeWak on 10,000 samples. Against the strongest SOTA baseline, FreqWak improves context-FID by 51.26% and correlational scores by 92.67%, while keeping the synthetic data quality statistically indistinguishable from the unwatermarked baseline. Moreover, owing to the phase invariance of non-DC components, FreqWak is provably immune to offset attacks under linear transformations, with a formal proof. Overall, FreqWak achieves competitive performance across all evaluated benchmarks and attack configurations. Our code is available as supplementary material.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.