Extend your brand profile by curating daily news.

New Watermarking Framework Embeds Copyright Marks Directly in AI Image Generation

By FisherVista
Researchers introduce Latent Seal, a watermarking method integrated into latent diffusion models, offering robust copyright protection and traceability for AI-generated images.
New Watermarking Framework Embeds Copyright Marks Directly in AI Image Generation

As artificial intelligence generates images at industrial scale, verifying their origin and authorship has become a pressing challenge. A new watermarking framework, Latent Seal, embeds high-capacity watermarks directly into the generation process of latent diffusion models (LDMs), rather than attaching them after the image is created. This approach aims to support copyright verification and help identify AI-generated content without visibly degrading image quality.

Developed by researchers from Macao Polytechnic University, Guangdong University of Technology, Jinan University, and the Institute of Automation, Chinese Academy of Sciences, the framework is detailed in a study published in Machine Intelligence Research (DOI:10.1007/s11633-025-1620-y). The team reports that Latent Seal places a latent-space encoder that blends a red-green-blue (RGB) watermark into the model's internal representation, while a paired decoder recovers the mark only from protected images. Tests show the method remains highly accurate after common edits and distortions, offering a practical route toward more traceable and accountable generative-image systems.

Traditional post-processing watermarks are easy to deploy but remain separate from the model and may be removed or bypassed. In-generation techniques integrate protection more deeply, but many carry limited information or lose reliability after compression, cropping, rotation, color adjustment, or targeted removal. Latent Seal addresses these challenges by embedding protection into the generation process, making provenance information durable enough for real online circulation.

The team built Latent Seal around Stable Diffusion 2.1 and assembled 74,247 generated images from prompts drawn from DiffusionDB and JourneyDB. The system freezes the original denoising network, clones and fine-tunes the variational autoencoder (VAE) decoder, and inserts a latent-space watermark encoder into an intermediate decoding block. A separate decoder learns to recover the target watermark from protected images and return a blank output for unprotected images, reducing false detection.

During training, an attack layer simulated ten common distortions, including brightness, contrast, and saturation changes, blur, noise, compression, flips, cropping, and rotation. In benchmark tests, watermarked images reached a peak signal-to-noise ratio of 44.29 decibels and a structural similarity index of 0.9933, while recovered watermarks achieved 39.19 decibels, 0.9971 structural similarity, and 0.9992 normalized cross-correlation. Latent Seal also retained the strongest extraction quality across every tested attack and added only 7.33 milliseconds during embedding and 2.26 milliseconds during extraction. Tests on Stable Diffusion XL and Stable Diffusion 3.5 further showed consistent performance across models and image resolutions.

“The aim is to preserve the visual quality users expect while giving model providers a practical way to verify origin after images have been edited or shared,” the authors said. “Our results suggest that strong watermark recovery and low visual impact can be achieved together.” The next step, they noted, is to improve recovery for visually complex watermarks and make the framework adaptable to new watermark designs without retraining the full system each time.

Latent Seal could support provenance checks for commercial image generators, social-media investigations, copyright disputes, content moderation, and digital-asset management, particularly where providers control the underlying model. Its ability to carry a full-color image offers more identifying capacity than simple binary signatures, while its resistance to routine edits could help marks survive ordinary online sharing. However, the current system must be retrained for each new watermark, and recovery becomes modestly less accurate as watermark textures and colors grow more complex. The researchers therefore propose frequency-domain feature fusion and a lightweight adapter for arbitrary watermarks. In practice, the method would work best alongside disclosure policies, metadata standards, and other content-authentication tools rather than as a stand-alone guarantee.

This work was funded by the Science and Technology Development Fund of Macau Special Administrative Region (SAR), China (No. 0053/2025/RIB2), and the Macao Polytechnic University, China (No. RP/FCA-04/2024). The study was published in Machine Intelligence Research, a journal sponsored by the Institute of Automation, Chinese Academy of Sciences and published by Springer. For more information about the research, visit the original source at https://doi.org/10.1007/s11633-025-1620-y.

FisherVista

FisherVista

@fishervista