acceptodds
Under review as a conference paper at ICLR 2027

ZeroStep: Rethinking Diffusion Inversion for Watermark Verification

Abstract

Embedding watermarks into the initial noise provides a natural mechanism for copyright protection and source attribution in diffusion generation. Yet existing verification methods still invert the generated image back to the initial watermarked noise, making costly diffusion inversion a standard step in watermark recovery. We revisit this requirement by tracing watermark evidence along the generation trajectory and find that, although similarity to the initial watermarked noise drops rapidly, watermark recoverability remains high even near the generation endpoint. This observation motivates ZeroStep, a zero-step watermark verification method that removes diffusion inversion entirely. Our method trains a lightweight LoRA adapter on the VAE encoder with trajectory supervision across timesteps and latent components, enabling direct watermark extraction without diffusion inversion. For robustness during online image distribution, we further leverage paired clean and distorted views to guide distortion-robust training. Experiments across diffusion and flow-matching backbones show that our method consistently outperforms state-of-the-art inversion-based methods. Notably, on the challenging SD v3.5 backbone, it improves watermark bit accuracy from 95.88% to 99.11% while reducing the deployed model size from 2.5B to 35.01M parameters. Moreover, the learned adapter can be reused across compatible model versions and scales, demonstrating strong cross-model adaptability. Code is available at https://anonymous.4open.science/r/ZeroStep-Release.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.