Latent Angular Watermarking with Provable Marginal Gaussianity and Characterized Correlation
Abstract
Latent domain watermarking for diffusion models embeds watermarks directly into the latent prior, enjoying non-intrusiveness to model parameters and seamless integration with the generation process. However, due to the violation of latent marginal Gaussianity or sensitivity to normal and malicious perturbations during latent inversion, existing methods are prone to watermark detection or removal attacks. A further overlooked problem is the violation of the i.i.d. latent condition after watermarking, which leads to latent correlation degradation and generation fidelity loss. Although this has been externally measured by FID, the internal correlation structure has yet to be rigorously characterized. To address the above issues, and motivated by the rotation-invariant property of isotropic Gaussian, we propose Latent Angular Watermarking (LAW), which encodes watermark bits as antipodal angles ( relative to reference pairs) between disjoint pairs of latent elements while preserving marginal Gaussianity. The antipodal (-separation) encoding maximizes geometric separation between bit values, providing maximal tolerance against normal and malicious latent distortions. We further propose a magnitude-driven variant, LAW-M, which anchors watermark bits in the most geometrically stable latent pairs, yielding additional robustness gains. Theoretically, we prove that the decoding angular error is inversely proportional to the norm of the latent pair, i.e., , and provide a rigorous characterization of the induced correlation degradation by deriving the closed-form covariance matrix of the watermarked latent, demonstrating that correlations are confined to a sparse, structured set of off-diagonal elements with fixed values. Extensive experiments demonstrate state-of-the-art robustness against a broad range of post-processing and regeneration attacks, together with the superior image fidelity among existing methods.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.