cs.CVSep 30, 2026

Persistent Watermarking of Text-to-Image Models

Authors: Dixi Yao, Kaiwen Chen, Tahseen Rabbani, Tian Li

Organizations: University of Chicago

Abstract

Text-to-image (T2I) generation is gaining increasing popularity with the general public, motivating the development of reliable mechanisms for copyrighting such models given their expensive training costs. An adversary may obtain and reuse a pretrained T2I model without authorization, and then serve a modified version through an API service. Such modifications may arise from ordinary downstream adaptation or deliberate attempts to erase ownership, including input-prompt preprocessing, model fine-tuning, and output post-processing. From the model owner's perspective, a key challenge is therefore to embed trigger data that remain persistent under such changes while preserving the model's normal image-generation capabilities. In this work, we propose a contrastive-style watermarking objective with a term that explicitly encourages the watermarked model to behave differently from the original model on trigger inputs. Experiments show substantially stronger trigger-data persistence than prior methods across a wide range of downstream modifications and deliberate attempts to weaken the watermark, resulting in higher detection rates, often approaching 100% TPR@FPR<10−410^{-4}.

Figures & tables

Appendix figures & tables40 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Linear Ensembles Wash Away Watermarks: On the Fragility of Distributional Perturbations in LLMs

    May 28, 2026Zhihao Wu, Gracia Gong, Qinglin Zhu +2Large Language Model WatermarksWatermarks

  2. Cert-LAS: Toward Certified Model Ownership Verification for Text-to-Image Diffusion Models via Layer-Adaptive Smoothing

    May 28, 2026Leyi Qi, Yiming Li, Siyuan Liang +2Dataset Ownership VerificationText-To-Image Diffusion Models

  3. One Prompt Is Enough: Watermark Laundering Through Foundation Image Models

    Sep 1, 2026Jidong Yang, Qi Li, Wei Zong +5WatermarksWireless Foundation Models