Maximize your thought leadership

New Watermarking Framework 'Latent Seal' Embeds Durable Provenance into AI-Generated Images

By Advos
Researchers have developed Latent Seal, a framework that embeds high-capacity watermarks during image generation in latent diffusion models, offering robust copyright verification and provenance tracking for AI-generated content.
New Watermarking Framework 'Latent Seal' Embeds Durable Provenance into AI-Generated Images

As artificial intelligence-generated images become increasingly realistic and widespread, the challenge of verifying their origin and ensuring copyright protection has grown more pressing. A research team has developed Latent Seal, a novel watermarking framework that embeds robust watermarks during the image generation process itself, rather than attaching them after creation. This approach aims to support copyright verification and provenance tracking for AI-generated content (AIGC) without visibly degrading image quality.

The method, reported in the journal Machine Intelligence Research on June 17, 2026, uses a latent-space encoder to blend a red-green-blue (RGB) watermark into the internal representation of latent diffusion models (LDMs), with a paired decoder recovering the mark only from protected images. Tests demonstrate that the watermark remains highly accurate after common edits and distortions, offering a practical solution for traceable and accountable generative-image systems.

Traditional post-processing watermarks are easy to deploy but remain separate from the model and can be removed or bypassed. In-generation techniques integrate protection more deeply, but many carry limited information or lose reliability after compression, cropping, rotation, or targeted removal. Latent Seal addresses these challenges by embedding watermarks during generation, making them visually unobtrusive and resilient to real-world manipulation.

The research team, from Macao Polytechnic University, Guangdong University of Technology, Jinan University, and the Institute of Automation, Chinese Academy of Sciences, built Latent Seal around Stable Diffusion 2.1, assembling 74,247 generated images and their latent representations from prompts in DiffusionDB and JourneyDB. The system freezes the denoising network, clones and fine-tunes the variational autoencoder (VAE) decoder, and inserts a latent-space watermark encoder into an intermediate decoding block. A separate decoder learns to recover the watermark from protected images and return a blank output for unprotected ones, reducing false detection.

During training, an attack layer simulated ten common distortions, including brightness, contrast, saturation changes, blur, noise, compression, flips, cropping, and rotation. Benchmark tests showed watermarked images achieved a peak signal-to-noise ratio of 44.29 decibels and a structural similarity index of 0.9933, while recovered watermarks reached 39.19 decibels, 0.9971 structural similarity, and 0.9992 normalized cross-correlation. Latent Seal also retained the strongest extraction quality across all attacks and added only 7.33 milliseconds during embedding and 2.26 milliseconds during extraction. Tests on Stable Diffusion XL and Stable Diffusion 3.5 showed consistent performance across models and resolutions.

“The aim is to preserve the visual quality users expect while giving model providers a practical way to verify origin after images have been edited or shared,” the authors said. “Our results suggest that strong watermark recovery and low visual impact can be achieved together.”

Latent Seal could support provenance checks for commercial image generators, social-media investigations, copyright disputes, content moderation, and digital-asset management, particularly where providers control the underlying model. Its ability to carry a full-color image offers more identifying capacity than simple binary signatures, and its resistance to routine edits could help marks survive ordinary online sharing.

However, the current system must be retrained for each new watermark, and recovery becomes modestly less accurate as watermark complexity increases. The researchers propose frequency-domain feature fusion and a lightweight adapter for arbitrary watermarks, and note that the method would work best alongside disclosure policies and other content-authentication tools.

The work was funded by the Science and Technology Development Fund of Macau SAR and Macao Polytechnic University. The full study is available at DOI: 10.1007/s11633-025-1620-y.

Advos

Advos

@advos