Learning to Watermark in the Latent Space of Generative Models
Sylvestre-Alvise Rebuffi, Tuan Tran, Valeriu Lacatusu, Pierre Fernandez, Tomáš Souček, Nikola Jovanović, Tom Sander, Hady Elsahar
Abstract
Existing approaches for watermarking AI-generated images often rely on post-hoc methods applied in pixel space, introducing computational overhead and potential visual artifacts. In this work, we explore latent space watermarking and introduce DistSeal, a unified approach for latent watermarking that works across both diffusion and autoregressive models. Our approach works by training post-hoc watermarking models in the latent space of generative models. We demonstrate that these latent watermarkers can be effectively distilled either into the generative model itself or into the latent decoder, enabling in-model watermarking. The resulting latent watermarks achieve competitive robustness while offering similar imperceptibility and up to 20x speedup compared to pixel-space baselines. Our experiments further reveal that distilling latent watermarkers outperforms distilling pixel-space ones, providing a solution that is both more efficient and more robust.
BibTeX
@inproceedings{
rebuffi2026learning,
title={Learning to Watermark in the Latent Space of Generative Models},
author={Sylvestre-Alvise Rebuffi and Tuan A. Tran and Valeriu Lacatusu and Pierre Fernandez and Tom{\'a}{\v{s}} Sou{\v{c}}ek and Nikola Jovanovi{\'c} and Tom Sander and Hady Elsahar and Alexandre Mourachko},
booktitle={Forty-third International Conference on Machine Learning},
year={2026},
url={https://openreview.net/forum?id=V6GG63yCtH}
}