SphericalMark: Third-Moment Preserving Diffusion Watermarks with Adaptive Augmentation Detection
Abstract
Diffusion watermarking embeds a learnable signature into the initial noise so that generated images remain traceable without degrading generation quality. Existing in-processing methods normalize this signature to match only the first two moments of the target Gaussian—mean and variance—leaving its skewness unconstrained; the resulting distributional mismatch is a structural limitation that current normalization schemes do not address. To address this gap, we propose SphericalMark, which introduces spherical third-moment normalization to explicitly constrain the third moment of the injected signature through a differentiable regularizer that combines bounded odd-symmetric transformation (tanh), re-centering, and norm restoration. This yields a watermark distribution more faithful to the target Gaussian while remaining fully end-to-end optimizable. To strengthen detection robustness, we further introduce an adaptive augmentation sampler (OAS) that continually reallocates training probability toward the perturbations on which the detector currently performs worst. Evaluated on Stable Diffusion 2.1, SphericalMark achieves 78% lower quality degradation than state-of-the-art SERUM (FID: 0.81 0.18) while maintaining competitive robustness (average TPR: 98.55% @ 1% FPR, within 1.5% of SERUM for 7/8 perturbations). We validate the distributional benefits through direct statistical measurement and demonstrate that SphericalMark offers a practical, drop-in refinement that better respects the target noise distribution without sacrificing efficiency.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.