Watermarking Autoregressive Image Generation
Nikola Jovanovic, Ismail Labiad, Tomás Soucek, Martin T. Vechev, Pierre Fernandez
Abstract
Watermarking the outputs of generative models has emerged as a promising approach for tracking their provenance. Despite significant interest in autoregressive image generation models and their potential for misuse, no prior work has attempted to watermark their outputs at the token level. In this work, we present the first such approach by adapting language model watermarking techniques to this setting. We identify a key challenge: the lack of reverse cycle-consistency (RCC), wherein re-tokenizing generated image tokens significantly alters the token sequence, effectively erasing the watermark. To address this and to make our method robust to common image transformations, neural compression, and removal attacks, we introduce (i) a custom tokenizer-detokenizer finetuning procedure that improves RCC, and (ii) a complementary watermark synchronization layer. As our experiments demonstrate, our approach enables reliable and robust watermark detection with theoretically grounded p-values. Code and models are available at https://github.com/facebookresearch/wmar.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5e35a52b-f84e-41ef-a315-857b2f7b0f5eCited by top-tier papers5
- Watermarking Diffusion Language ModelsThibaud Gloaguen, Robin Staab, Nikola Jovanović, Martin VechevICLR 2026 · 13 citations
- Data Provenance for Image Auto-Regressive GenerationBihe Zhao, Louis Kerner, Michel Meintz, Tameem Bakr et al.ICLR 2026 · 5 citations
- ClusterMark: Towards Robust Watermarking for Autoregressive Image Generators with Visual Token ClusteringDenis Lukovnikov, Andreas Müller, Erwin Quiring, Asja FischerCVPR 2026 · 3 citations
- Hidden in Plain Tokens: Simply Robust, Gradient-Free Watermark for Synthetic AudioGeorgios Milis, Yubin Qin, Yihan Wu, Heng HuangICML 2026 · 2 citations
- Learning to Watermark in the Latent Space of Generative ModelsSylvestre-Alvise Rebuffi, Tuan Tran, Valeriu Lacatusu, Pierre Fernandez et al.ICML 2026 · 1 citation
Builds on49
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
- Zero-Shot Text-to-Image GenerationAditya Ramesh, Mikhail Pavlov, Gabriel Goh, Scott Gray et al.ICML 2021 · 6,356 citations
- SDXL: Improving Latent Diffusion Models for High-Resolution Image SynthesisDustin Podell, Zion English, Kyle Lacey, Andreas Blattmann et al.ICLR 2024 · 4,569 citations
- Visual Autoregressive Modeling: Scalable Image Generation via Next-Scale PredictionKeyu Tian, Yi Jiang, Zehuan Yuan, Bingyue Peng et al.NeurIPS 2024 · 1,199 citations
Related papers
- BitMark: Watermarking Bitwise Autoregressive Image Generative ModelsLouis Kerner, Michel Meintz, Bihe Zhao, Franziska Boenisch et al.NeurIPS 2025 · 6 citations
- You Can Have a Second Chance: Unbiased and Multi-bit Watermarking for Diffusion Language Models with Regret-based RemaskingKe Yang, Dongyang Liang, Jing Yu, Shuguang Yuan et al.ACL 2026
- IPMark: A Sentence-Level Watermark for LLMs with Hierarchical Personalization and Efficient DetectionWenbo An, Lianwei Wu, Zehao WangICML 2026
- Linear Ensembles Wash Away Watermarks: On the Fragility of Distributional Perturbations in LLMsZhihao Wu, Gracia Gong, Qinglin Zhu, Yudong Chen et al.ICML 2026
- No Free Lunch in LLM Watermarking: Trade-offs in Watermarking Design ChoicesQi Pang, Shengyuan Hu, Wenting Zheng, Virginia SmithNeurIPS 2024 · 56 citations
