DERO: Diffusion-Model-Erasure Robust Watermarking
Han Fang, Kejiang Chen, Yupeng Qiu, Zehua Ma, Weiming Zhang, Ee-Chien Chang
Abstract
The effective denoising demonstrated by the latent diffusion model poses a new threat to image watermarking, as attackers can erase the watermark by performing a forward diffusion, followed by backward denoising. While such denoising might introduce large distortion in the pixel domain, the image semantics remain similar. Unfortunately, most existing robust watermarking methods fail to tackle such an erasure attack since they are primarily designed for traditional channel distortions. To address such issue, this paper proposed DERO, a diffusion-model-erasure robust watermarking framework. Based on the frequency domain analysis of the diffusion model's denoising process, we designed a destruction and compensation noise layer (DCNL) to approximate the distortion effects caused by latent diffusion model erasure (LDE). In detail, DCNL consists of a multi-scale low-pass filtering and a white noise compensation process, where the high-frequency components of the image are first obliterated, and then full-frequency components are enriched with white noise. Such a process broadly simulates the LDE distortions. Besides, on the extraction side, we cascaded a pre-trained variational autoencoder before the decoder to extract the watermark in the latent domain, which closely adapts to the operation domain of the LDE process. Meanwhile, to improve the robustness of the decoder, we also design a latent feature augmentation (LFA) operation on the latent feature. Throughout the end-to-end training with the DCNL and LFA, DERO can successfully achieve robustness against LDE. Our experimental results demonstrate the effectiveness and the generalizability of the proposed framework. The LDE robustness is significantly improved from 75% with SOTA methods to an impressive 96% with DERO.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 14866b0b-b287-44f4-87db-c9ee807a8dd5Cited by top-tier papers2
- ImageSentinel: Protecting Visual Datasets from Unauthorized Retrieval-Augmented Image GenerationZiyuan Luo, Yangyi Zhao, Ka Chun Cheung, Simon See et al.NeurIPS 2025 · 5 citations
- RoPaSS: Robust Watermarking for Partial Screen-Shooting ScenariosZehua Ma, Han Fang, Xi Yang, Kejiang Chen et al.AAAI 2025 · 4 citations
Related papers
- Semantic Watermarking Reinvented: Enhancing Robustness and Generation Quality with Fourier IntegritySung Ju Lee, Nam Ik ChoICCV 2025 · 5 citations
- Attack-Resilient Image Watermarking Using Stable DiffusionLijun Zhang, Xiao Liu, Antoni Viros Martin, Cindy Xiong Bearfield et al.NeurIPS 2024 · 62 citations
- Guidance Watermarking for Diffusion ModelsEnoal Gesny, Eva Giboulot, Teddy Furon, Vivien ChappelierICLR 2026 · 5 citations
- Flexible and Secure Watermarking for Latent Diffusion ModelCheng Xiong, Chuan Qin, Guorui Feng, Xinpeng ZhangACM MM 2023 · 50 citations
- ROAR: Reducing Inversion Error in Generative Image WatermarkingHanyi Wang, Han Fang, Shi-Lin Wang, Ee-Chien ChangICCV 2025 · 1 citation
