cs.CVSep 30, 2026

Semantic Watermarking for Malicious Image Manipulation Detection

Authors: Yoonseo Kim, Seungwoo Baek, Junyoung Park

Organizations: Korea University, Seoul, South Korea.

Abstract

The proliferation of high-fidelity generative editing models has made it possible to inject violent or sexual content into otherwise ordinary images while preserving visual plausibility, with concrete consequences for public discourse and vulnerable populations. We propose a robust semantic watermarking framework that reframes the watermark as a recoverable semantic reference rather than an opaque identifier. Our framework combines a ββ-VAE-based binary watermark (CLIP-VAE) with explicit channel-aware training---random bit-flip noise is injected during training so that the decoder learns graceful degradation under the noisy watermarking channel. As a downstream application, a lightweight module SDA-Net uses the recovered semantic embedding to expose not only whether but in which semantic direction an image has been altered. In a 5-way comparison against representative binary hashing baselines (SimHash, ITQ, HashNet, and their robust-MLP variants), CLIP-VAE achieves the highest reconstruction cosine similarity to the original CLIP embedding under realistic InstructPix2Pix bit-error rates, and uniquely supports direction-of-drift detection---a forensic complement to existing content-moderation pipelines.

Figures & tables

Appendix figures & tables8 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Are Watermarked Images Editable? SafeMark for Watermark-Preserving Text-Guided Image Editing

    May 19, 2026Xiaodong Wu, Qi Li, Xiangman Li +3WatermarksDiffusion-Based Image Editing

  2. Robust Watermarks Meet Backdoored Models: Evading Diffusion Semantic Watermarks via Stealthy Backdoor

    Aug 1, 2026Jinyuan Liu, Tianshuo Cong, Pei Li +4WatermarksWatermarking

  3. LoT-Pass: Long-term-robust Image Watermarking for Image to Video Generation

    Sep 22, 2025Guanjie Wang, Zehua Ma, Han Fang +1WatermarksWatermarking