EditR: Robust Image Watermarking by Learning How Generative Editing Transforms the Watermark
Abstract
Instruction-guided generative editing replaces objects or repaints scenes, often without visible traces—challenging invisible watermarking, whose value depends on recovering provenance and ownership after modification. Robust watermarking trains an embed–distort–extract pipeline against simulated attacks in a differentiable distortion layer. A generative editor, however, cannot take that place: its sampling pipeline resists stable gradient-based training. A natural remedy is to simulate the editor, yet what matters for recovery is not the edited image’s appearance but how editing transforms the watermark perturbation. We therefore identify the learning target as the editor’s response to the embedded perturbation and introduce DERS, a Differentiable Editing-Response Simulator. Trained on paired clean and watermarked edits, this differentiable surrogate predicts only this response, adds it to the clean edit—content generation inherited, not simulated—to take the editor’s place in the distortion layer. The watermark, however, is embedded at 256×256, while the editor works at native resolution on its own working grid, where naive resizing breaks the watermark’s message-bearing structure; we therefore introduce Content- and Geometry-aware Residual Transfer (CART) to adapt it to image content and the editor’s preprocessing geometry. We present EditR, an end-to-end framework integrating the two in two stages: the watermark is first trained against common distortions, and DERS is then pretrained on the paired edits and frozen. The embedder, extractor, and CART are trained against this fixed simulator—faithful to the editor’s observed response rather than drifting with the watermark it judges. On five Qwen-Image-Edit operations, EditR reaches 90.76% mean bit accuracy, an absolute gain of 12.00 percentage points over the strongest evaluated baseline, while maintaining 47.33 dB PSNR. It remains stable across the tested native resolutions and transfers without retraining, reaching 87.76% and 84.40% mean bit accuracy on JoyAI-Image-Edit and Doubao-Seedream-4.5.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.