arrow
Return

Distributor-centric model watermarking for image generative models

delete2025-09-06
delete0
PRE
AI
J
Jianwei Fei
Y
Yunshu Dai
W
Wenyuan Yang
夏志华 (Zhihua Xia)
DOI:10.1016/j.knosys.2025.114422delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In this paper, we present an efficient watermarking method for generative models that allows the developer (distributor) to create model instances with unique watermarks that are naturally embedded in their generated images. To achieve this, we replace the convolution layers of the generator with Watermark-Informed Convolution (WIC) in the pre-trained model. WIC consists of N parallel standard convolution kernels, and a watermark encoder transforms watermarks into coefficients that modulate these parallel kernels. Once fine-tuned with WIC, the distributor only needs to generate the coefficients and use them to combine the parallel kernels in WIC to create a generator with the desired watermark. Importantly, the combined kernel is identical to a standard convolution kernel, ensuring no additional inference overhead. Our method is highly scalable and efficient, making it practical for forensic capabilities by embedding watermarks directly into model parameters, remaining robust against common attacks such as model pruning or image compression. Furthermore, we evaluate our method on scenarios with highly aggressive compression or advanced adversarial attacks, and the trade-offs between watermark capacity, robustness, and computational efficiency. Experiments on multiple generative models demonstrate that the proposed method is architecture-agnostic, achieves high fidelity, and provides superior robustness compared to the existing methods.

Journal

K
Knowledge-Based Systems
IF:
7.6
Papers:
1.2W
Citations:
4.5W

Organization

S
sun yat-sen university
Scholars:
1.9W
Papers: 6.4K
Citations: 14
J
jinan university
Scholars:
4.3W
Papers: 2.6W
Citations: 38