Journal of Information Security Reserach ›› 2026, Vol. 12 ›› Issue (7): 662-671.

Previous Articles    

A Unified Distributionpreserving Residual Watermark Embedding Method for Diffusion Models

Wei Lan, Zhao Wanying, Zhou Jingxian, and Guo Peng   

  • Published:2026-07-24

面向扩散模型的统一分布保持残差水印嵌入方法

卫兰,赵婉莹,周景贤,国鹏   

Abstract: Aiming at the challenge that diffusion model watermarking can hardly achieve both generation quality preservation and antidistortion robustness, this paper proposes a unified distributionpreserving residual embedding method. Without modifying the diffusion backbone parameters, the proposed method adopts a twostage strategy. First, latent variables are mapped to a uniform distribution using the cumulative distribution function of the Gaussian distribution, and watermark bits are embedded via interval partitioning and inverse mapping, ensuring that the latent distribution remains unchanged. Second, a lightweight residual module is inserted into the midblock of the UNet, where watermark bits are projected and injected into feature maps. Only this module is trained, achieving watermark embedding with minimal extremely small perturbations. The training phase jointly optimizes diffusion reconstruction loss and watermark prediction loss. Experiments on Stable Diffusion 2.1 demonstrate that the method maintains high visual fidelity of watermarked images, and the perturbation amplitude is far below the perceptual threshold. Under various distortions scenarios including JPEG compression, cropping, Gaussian noise, brightness and contrast adjustments, color quantization, and Diffwa(diffusion models for watermark attack) reconstruction, bit accuracy consistently exceeds 90%. Particularly, nearperfect accuracy is achieved under distortionfree and Diffwa reconstruction conditions, effectively balancing generation quality and robustness.

Key words: diffusion models; digital watermarking; distribution preservation; residual embedding; robustness

摘要: 针对扩散模型水印在“生成质量保持”与“抗失真鲁棒”之间难以兼顾的问题,提出一种统一分布保持残差嵌入方法(unified distributionpreserving residual embedding method, UDPRE).在不改变扩散主干网络参数的前提下,该方法采用两级策略:其一,在潜在空间采样阶段,通过高斯分布的累积分布函数将潜变量映射为均匀分布序列,并根据水印比特信息进行区间划分和反向映射,确保嵌入后潜在变量的整体分布保持不变;其二,在UNet中层插入轻量级残差模块,将水印比特投影后注入特征图,通过训练该模块实现以极小扰动的水印嵌入.训练阶段联合优化扩散重建损失与水印预测损失.基于Stable Diffusion 2.1的实验表明:该方法嵌入水印后图像视觉保真度高,扰动幅度远低于感知阈值;在JPEG压缩、裁剪、高斯噪声、亮度与对比度调整、颜色量化和Diffwa(diffusion models for watermark attack)重建等多种失真场景下,比特恢复准确率始终超过90%,尤其在无失真和Diffwa重建条件下表现出显著优势,有效兼顾了生成质量与鲁棒性.

关键词: 扩散模型;数字水印;分布保持;残差嵌入;鲁棒性

CLC Number: