dorsal/arxiv
View SchemaAttack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection
| Authors | Qingyu Liu, Yitao Zhang, Zhongjie Ba, Chao Shuai, Peng Cheng, Tianhang Zheng, Zhibo Wang |
|---|---|
| Categories | |
| ArXiv ID | 2601.06639vv1 |
| URL | https://arxiv.org/abs/2601.06639 |
| License | http://arxiv.org/licenses/nonexclusive-distrib/1.0/ |
Abstract
Protecting the copyright of user-generated AI images is an emerging challenge as AIGC becomes pervasive in creative workflows. Existing watermarking methods (1) remain vulnerable to real-world adversarial threats, often forced to trade off between defenses against spoofing and removal attacks; and (2) cannot support semantic-level tamper localization. We introduce PAI, a training-free inherent watermarking framework for AIGC copyright protection, plug-and-play with diffusion-based AIGC services. PAI simultaneously provides three key functionalities: robust ownership verification, attack detection, and semantic-level tampering localization. Unlike existing inherent watermark methods that only embed watermarks at noise initialization of diffusion models, we design a novel key-conditioned deflection mechanism that subtly steers the denoising trajectory according to the user key. Such trajectory-level coupling further strengthens the semantic entanglement of identity and content, thereby further enhancing robustness against real-world threats. Moreover, we also provide a theoretical analysis proving that only the valid key can pass verification. Experiments across 12 attack methods show that PAI achieves 98.43\% verification accuracy, improving over SOTA methods by 37.25\% on average, and retains strong tampering localization performance even against advanced AIGC edits. Our code is available at https://github.com/QingyuLiu/PAI.
{
"annotation_id": "d27a811a-f3eb-4065-8ea5-27bd8971c371",
"date_created": "2026-02-17T05:53:08.446000Z",
"date_modified": "2026-02-17T05:53:08.446000Z",
"file_hash": "c1b2f6272a7b6a9731478fd26a80d4ae1f97df7bb380c274cda55b6b3a9d8f1e",
"private": false,
"record": {
"abstract": "Protecting the copyright of user-generated AI images is an emerging challenge as AIGC becomes pervasive in creative workflows. Existing watermarking methods (1) remain vulnerable to real-world adversarial threats, often forced to trade off between defenses against spoofing and removal attacks; and (2) cannot support semantic-level tamper localization. We introduce PAI, a training-free inherent watermarking framework for AIGC copyright protection, plug-and-play with diffusion-based AIGC services. PAI simultaneously provides three key functionalities: robust ownership verification, attack detection, and semantic-level tampering localization. Unlike existing inherent watermark methods that only embed watermarks at noise initialization of diffusion models, we design a novel key-conditioned deflection mechanism that subtly steers the denoising trajectory according to the user key. Such trajectory-level coupling further strengthens the semantic entanglement of identity and content, thereby further enhancing robustness against real-world threats. Moreover, we also provide a theoretical analysis proving that only the valid key can pass verification. Experiments across 12 attack methods show that PAI achieves 98.43\\% verification accuracy, improving over SOTA methods by 37.25\\% on average, and retains strong tampering localization performance even against advanced AIGC edits. Our code is available at https://github.com/QingyuLiu/PAI.",
"arxiv_id": "2601.06639",
"authors": [
"Qingyu Liu",
"Yitao Zhang",
"Zhongjie Ba",
"Chao Shuai",
"Peng Cheng",
"Tianhang Zheng",
"Zhibo Wang"
],
"categories": [
"cs.CR",
"cs.AI"
],
"license": "http://arxiv.org/licenses/nonexclusive-distrib/1.0/",
"title": "Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection",
"url": "https://arxiv.org/abs/2601.06639",
"version": "v1"
},
"schema_id": "dorsal/arxiv",
"source": {
"execution_id": "953b487c-c647-42d1-8db4-b7ff7ea17606",
"id": "arXiv Dataset",
"type": "Model",
"variant": "snapshot-2026-01-17",
"version": "0.1.0"
},
"user_id": 1000002
}