acceptodds
Under review as a conference paper at ICLR 2027

EditR: Robust Image Watermarking by Learning How Generative Editing Transforms the Watermark

Abstract

Instruction-guided generative editing replaces objects or repaints scenes, often without visible traces—challenging invisible watermarking, whose value depends on recovering provenance and ownership after modification. Robust watermarking trains an embed–distort–extract pipeline against simulated attacks in a differentiable distortion layer. A generative editor, however, cannot take that place: its sampling pipeline resists stable gradient-based training. A natural remedy is to simulate the editor, yet what matters for recovery is not the edited image’s appearance but how editing transforms the watermark perturbation. We therefore identify the learning target as the editor’s response to the embedded perturbation and introduce DERS, a Differentiable Editing-Response Simulator. Trained on paired clean and watermarked edits, this differentiable surrogate predicts only this response, adds it to the clean edit—content generation inherited, not simulated—to take the editor’s place in the distortion layer. The watermark, however, is embedded at 256×256, while the editor works at native resolution on its own working grid, where naive resizing breaks the watermark’s message-bearing structure; we therefore introduce Content- and Geometry-aware Residual Transfer (CART) to adapt it to image content and the editor’s preprocessing geometry. We present EditR, an end-to-end framework integrating the two in two stages: the watermark is first trained against common distortions, and DERS is then pretrained on the paired edits and frozen. The embedder, extractor, and CART are trained against this fixed simulator—faithful to the editor’s observed response rather than drifting with the watermark it judges. On five Qwen-Image-Edit operations, EditR reaches 90.76% mean bit accuracy, an absolute gain of 12.00 percentage points over the strongest evaluated baseline, while maintaining 47.33 dB PSNR. It remains stable across the tested native resolutions and transfers without retraining, reaching 87.76% and 84.40% mean bit accuracy on JoyAI-Image-Edit and Doubao-Seedream-4.5.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.