Multi-Bit Watermarking with Semantic Integrity for Binary-Token Visual Generative Models
Abstract
The widespread deployment of large-scale image generation models raises urgent questions about provenance, attribution, and content authenticity. We present a training-free multi-bit watermarking framework for binary-token visual autoregressive models. The key idea is to treat the model's latent binary variables as redundant watermark carriers: each payload bit is assigned to many token-bit positions, and generation is steered only through positions that can be modified at low semantic cost. We investigate two visual autoregressive models with different generation mechanisms: Infinity, where selected uncertain bits at the finest scale are forced after sampling, and BiGR, where Bernoulli marginals are softly biased during bidirectional masked prediction. Extraction is purely feed-forward: the image is re-encoded through the frozen tokenizer and the payload is recovered by majority voting over the carrier sets. The framework supports variable-length payloads (16, 32, and 64 bits) and, for Infinity, achieves near-perfect bit accuracy on COCO-prompted images with negligible degradation to image quality as measured by FID, KID, and CLIP Score. Building on the multi-bit capacity, we introduce a semantic integrity mechanism: the watermark payload encodes a DINOHash perceptual fingerprint of the generated image, enabling post-hoc detection of semantic tampering. Because the watermark resides in latent token space, it can persist through pixel-level edits, while the perceptual hash of a tampered image diverges from the recovered payload—revealing manipulation.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.