PapersWithELO
← ICLR 2024 leaderboard

A Recipe for Watermarking Diffusion Models

Yunqing Zhao, Tianyu Pang, Chao Du, Xiao Yang, Ngai-man Cheung, Min Lin

fairness, safety & privacyDiffusion ModelsWatermarkingCopyright Protection
9.60100
Fused
band ≈ ±15 pct pts (from σ = 0.30)
8.90100
Mimo
band ≈ ±21 pct pts (from σ = 0.42)
10.00100
DeepSeek
band ≈ ±21 pct pts (from σ = 0.42)

OpenReview ground truth

Rejected

TL;DR — We conduct comprehensive ablation studies and propose a practical recipe for watermarking diffusion models, such as large-scale text-to-image models like Stable Diffusion.

Abstract

Diffusion models (DMs) have demonstrated advantageous potential on generative tasks. Widespread interest exists in incorporating DMs into downstream applications, such as producing or editing photorealistic images. However, practical deployment and unprecedented power of DMs raise legal issues, including copyright protection and monitoring of generated content. In this regard, watermarking has been a proven solution for copyright protection and content monitoring, but it is underexplored in the DMs literature. Specifically, DMs generate samples from longer tracks and may have newly designed multimodal structures, necessitating the modification of conventional watermarking pipelines. To this end, we conduct comprehensive analyses and derive a recipe for efficiently watermarking state-of-the-art DMs (e.g., Stable Diffusion), via training from scratch or finetuning. Our recipe is straightforward but involves empirically ablated implementation details, providing a foundation for future research on watermarking DMs.

Author context

Most prolific author: 11 submissions (credibility 0.71).

Delta if applied: -0.1 percentile

Aggregate statistics only — no individual author rankings.

Ranking trajectory

Percentile by tournament round — convergence indicates rating stability.

Battle history — 32 comparisons

Ranked above opponent in 33% of matchups.

Judge assessments

Mean overall score 0.0 ± 0.0 (n = 32)