Watermark Anything With Localized Messages
Tom Sander, Pierre Fernandez, Alain Oliviero Durmus, Teddy Furon, Matthijs Douze
Abstract
Image watermarking methods are not tailored to handle small watermarked areas. This restricts applications in real-world scenarios where parts of the image may come from different sources or have been edited. We introduce a deep-learning model for localized image watermarking, dubbed the Watermark Anything Model (WAM). The WAM embedder imperceptibly modifies the input image, while the extractor segments the received image into watermarked and non-watermarked areas and recovers one or several hidden messages from the areas found to be watermarked. The models are jointly trained at low resolution and without perceptual constraints, then post-trained for imperceptibility and multiple watermarks. Experiments show that WAM is competitive with state-of-the art methods in terms of imperceptibility and robustness, especially against inpainting and splicing, even on high-resolution images. Moreover, it offers new capabilities: WAM can locate watermarked areas in spliced images and extract distinct 32-bit messages with less than 1 bit error from multiple small regions -no larger than 10% of the image surface -even for small 256 × 256 images. Training and inference code and model weights are available at github.com/facebookresearch/watermark-anything.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f75d6fb-36d8-4ae6-89a3-37c8dde62407Cited by top-tier papers17
- SEAL: Semantic Aware Image WatermarkingKasra Arabi, R. Teal Witter, Chinmay Hegde, Niv CohenICCV 2025 · 22 citations
- Mask Image WatermarkingRunyi Hu, Jie Zhang, Shiqian Zhao, Nils Lukas et al.NeurIPS 2025 · 18 citations
- Watermark-based Attribution of AI-Generated ContentZhengyuan Jiang, Moyang Guo, Yuepeng Hu, Yupu Wang et al.ICLR 2026 · 11 citations
- StableGuard: Towards Unified Copyright Protection and Tamper Localization in Latent Diffusion ModelsHaoxin Yang, Bangzhen Liu, Xuemiao Xu, Cheng Xu et al.NeurIPS 2025 · 5 citations
- NoisePrints: Distortion-Free Watermarks for Authorship in Private Diffusion ModelsNir Goren, Oren Katzir, Abhinav Nakarmi, Eyal Ronen et al.ICLR 2026 · 5 citations
Builds on31
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Segment AnythingAlexander Kirillov, Eric Mintun, Nikhila Ravi, Hanzi Mao et al.ICCV 2023 · 13,211 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Emerging Properties in Self-Supervised Vision TransformersMathilde Caron, Hugo Touvron, Ishan Misra, Hervé Jégou et al.ICCV 2021 · 8,921 citations
Related papers
- On the Coexistence and Ensembling of WatermarksAleksandar Petrov, Shruti Agarwal, Philip H. S. Torr, Adel Bibi et al.NeurIPS 2025 · 9 citations
- Practical Deep Dispersed Watermarking with Synchronization and FusionHengchang Guo, Qilong Zhang, Junwei Luo, Feng Guo et al.ACM MM 2023 · 19 citations
- Achieving Resolution-Agnostic DNN-based Image Watermarking: A Novel Perspective of Implicit Neural RepresentationYuchen Wang, Xingyu Zhu, Guanhui Ye, Shiyao Zhang et al.ACM MM 2024 · 6 citations
- Robust Multi-bit Text Watermark with LLM-based ParaphrasersXiaojun Xu, Jinghan Jia, Yuanshun Yao, Yang Liu et al.ICML 2025
- Distortion Agnostic Deep WatermarkingXiyang Luo, Ruohan Zhan, Huiwen Chang, Feng Yang et al.CVPR 2020
