Search papers, labs, and topics across Lattice.
The paper introduces Dual-Guard, a dual-channel watermarking framework for diffusion-generated images that provides both provenance verification and tamper localization. It embeds a Gaussian Shading watermark in the initial noise for global provenance and a Latent Fingerprint Codec in the final latent space for content anchoring. Dual-Guard achieves high accuracy in detecting reprompting, diffusion editing, and local tampering attacks while maintaining low false positive rates on clean images.
Diffusion image watermarks can now simultaneously resist adversarial framing and pinpoint tampering, thanks to a dual-channel approach.
The rapid adoption of diffusion-based generative models has intensified concerns over the attribution and integrity of AI-generated content (AIGC). Existing single-domain watermarking methods either fail under regeneration, remain vulnerable to black-box reprompting that enables adversarial framing, or provide no spatial evidence for tampered regions. We propose Dual-Guard, a dual-channel latent watermarking framework for practical provenance verification, framing resistance, and region-level tamper localization. Dual-Guard combines two complementary anchors: a Gaussian Shading watermark in the initial diffusion noise as a global provenance signal, and a Latent Fingerprint Codec in the final denoised latent as a structured content anchor. Reprompting tends to preserve the former while breaking the latter, whereas localized edits disturb the content anchor only in tampered regions. In Full mode on a 2,400-sample benchmark, Dual-Guard keeps clean-image authentication false rejection and tamper false alarm below one half of one percent, while maintaining near-complete detection under reprompting, diffusion editing, and eight local tampering attacks.