Geometry-Based Watermarking for Vector Databases
Abstract
Vector databases are expensive to construct but can be readily replicated, creating a need for effective mechanisms to establish their provenance. Watermarking provides a potential solution; however, conventional coordinate-based watermarks can be disrupted by transformations that preserve Euclidean nearest-neighbor retrieval. To address this limitation, we propose a watermarking scheme that leverages local geometric structure both to identify watermark carriers and to encode the watermark message. In particular, distance ratios and angles provide invariant geometric fingerprints that remain stable under a broad class of transformations. Secret keys are then used to select watermark carriers based on these fingerprints, determine message positions, and select the angles used to encode individual bits. Verification requires only the suspect vector database and the corresponding secret key. We empirically evaluate the proposed scheme on four public datasets, with 50 trials conducted per dataset. Across a range of attacks, including multiple similarity transformations, vector shuffling, and index reconstruction, the method achieves a true-positive rate close to 100% at a 1% false-positive rate. Additional experiments evaluate the scheme's robustness to further forms of data modification and quantify the retrieval-quality loss incurred by attacks designed to compromise the watermark.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.