T2SMark: Balancing Robustness and Diversity in Noise-as-Watermark for Diffusion Models
Jindong Yang, Han Fang, Weiming Zhang, Nenghai Yu, Kejiang Chen
Abstract
Diffusion models have advanced rapidly in recent years, producing high-fidelity images while raising concerns about intellectual property protection and the misuse of generative AI. Image watermarking for diffusion models, particularly Noise-as-Watermark (NaW) methods, encode watermark as specific standard Gaussian noise vector for image generation, embedding the infomation seamlessly while maintaining image quality. For detection, the generation process is inverted to recover the initial noise vector containing the watermark before extraction. However, existing NaW methods struggle to balance watermark robustness with generation diversity. Some methods achieve strong robustness by heavily constraining initial noise sampling, which degrades user experience, while others preserve diversity but prove too fragile for real-world deployment. To address this issue, we propose T2SMark, a two-stage watermarking scheme based on Tail-Truncated Sampling (TTS). Unlike prior methods that simply map bits to positive or negative values, TTS enhances robustness by embedding bits exclusively in the reliable tail regions while randomly sampling the central zone to preserve the latent distribution. Our two-stage framework then ensures sampling diversity by integrating a randomly generated session key into both encryption pipelines. We evaluate T2SMark on diffusion models with both U-Net and DiT backbones. Extensive experiments show that it achieves an optimal balance between robustness and diversity. Our code is available at https://github.com/0xD009/T2SMark.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ea5ba9c8-fef0-402d-aa63-65433c28ea42Cited by top-tier papers2
- MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent ManipulationJie Cao, Qi Li, Zelin Zhang, Xiaodong Wu et al.USENIX Security 2026 · 1 citation
- WMVLM: Evaluating Diffusion Model Image Watermarking via Vision-Language ModelsZijin Yang, Yu Sun, Kejiang Chen, jiawei zhao et al.ICML 2026
Builds on19
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
Related papers
- MaxMark: High-Capacity Diffusion-Native Watermarking via Robust and Invertible Latent EmbeddingXuanhang Chang, Zhonghao Yang, Cheng Zhuo, YU LICVPR 2026
- Your Text Encoder Can Be an Object-Level Watermarking ControllerNaresh Kumar Devulapally, Mingzhen Huang, Vishal Asnani, Shruti Agarwal et al.ICCV 2025 · 1 citation
- GaussMarker: Robust Dual-Domain Watermark for Diffusion ModelsKecen Li, Zhicong Huang, Xinwen Hou, Cheng HongICML 2025
- TAG-WM: Tamper-Aware Generative Image Watermarking via Diffusion Inversion SensitivityYuzhuo Chen, Zehua Ma, Han Fang, Weiming Zhang et al.ICCV 2025 · 4 citations
- SIGMark: Scalable In-Generation Watermark with Blind Extraction for Video DiffusionXinjie zhu, Zijing Zhao, Hui Jin, Qingxiao Guo et al.ICLR 2026 · 1 citation
