Paper 2025/1620

The Coding Limits of Robust Watermarking for Generative Models

Danilo Francati, Sapienza University of Rome
Yevin Nikhel Goonatilake, George Mason University
Shubham Pawar, Royal Holloway University of London
Daniele Venturi, Sapienza University of Rome
Giuseppe Ateniese, George Mason University
Abstract

We study a basic question about cryptographic watermarking for generative models: how reliable can a watermark remain when an adversary is allowed to corrupt the encoded signal? To address this question, we introduce a minimal coding abstraction that we call a zero-bit tamper-detection code. This is a secret-key procedure that samples a pseudorandom codeword and, given a candidate word, decides whether it should be treated as unmarked content or as the result of tampering with a valid codeword. It captures the two core requirements of robust watermarking: soundness and tamper detection. Within this abstraction we prove a sharp unconditional limit on robustness to independent symbol corruption. For an alphabet of size $q$, there is a critical corruption rate of $1−1/q$ such that no scheme with soundness, even relaxed to allow a fixed constant false positive probability on random content, can reliably detect tampering once an adversary can change more than this fraction of symbols. In particular, in the binary case no cryptographic watermark can remain robust if more than half of the encoded bits are modified. We also show that this threshold is tight by giving simple information-theoretic constructions that achieve soundness and tamper detection for all strictly smaller corruption rates. We then test experimentally whether this limit appears in practice by looking at the recent watermarking for images of Gunn, Zhao, and Song (ICLR 2025). We show that a simple crop and resize operation reliably flipped about half of the latent signs and consistently prevented belief-propagation decoding from recovering the codeword, erasing the watermark while leaving the image visually intact.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Published elsewhere. IEEE Euro S&P 2026
Keywords
watermarkingpseudorandom codesimpossibilitygenerative modelsdiffusion models
Contact author(s)
francati @ di uniroma1 it
History
2026-05-02: last of 3 revisions
2025-09-08: received
See all versions
Short URL
https://ia.cr/2025/1620
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1620,
      author = {Danilo Francati and Yevin Nikhel Goonatilake and Shubham Pawar and Daniele Venturi and Giuseppe Ateniese},
      title = {The Coding Limits of Robust Watermarking for Generative Models},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1620},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1620}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.