Proof-of-Authorship for Diffusion-based AI Generated Content
cs.CR
Submitted: 2026-03-18
Updated: 2026-09-21
License: http://creativecommons.org/licenses/by/4.0/
The gist: Recent advancements in AI-generated content (AIGC) have introduced new challenges in intellectual property protection and the authentication of generated objects.
Terminology
Abstract
Recent advancements in AI-generated content (AIGC) have introduced new challenges in intellectual property protection and the authentication of generated objects. We focus on scenarios in which an author seeks to assert authorship of an object generated using latent diffusion models (LDMs), in the presence of adversaries who attempt to falsely claim authorship of objects they did not create. While proof-of-ownership has been studied in the context of multimedia content through techniques such as time-stamping and watermarking, these approaches face notable limitations. In contrast to traditional content creation sources (e.g., cameras), the LDM generation process offers greater control to the author. Specifically, the random seed used during generation can be deliberately chosen. By binding the seed to the author's identity using cryptographic functions, the author can assert to be the creator of the object. We refer to this stronger guarantee as proof-of-authorship, since only the creator of the object can legitimately claim the object. This contrasts with proof-of-ownership via time-stamping or watermarking, where any entity could potentially claim ownership of an object by being the first to timestamp or embed the watermark. We propose a proof-of-authorship framework involving a probabilistic adjudicator who quantifies the probability that a claim is false. Furthermore, unlike prior approaches, the proposed framework does not involve any secret. We explore various attack scenarios and analyze design choices using Stable Diffusion 2.1 and XL as representative case studies.
Sources
- Stable Signature is Unstable: Removing Image Watermark from Diffusion Models
- Watermark Robustness and Radioactivity May Be at Odds in Federated Learning
- NoisePrints: Distortion-Free Watermarks for Authorship in Private Diffusion Models
- On Memorization in Diffusion Models
- Enhancing Variational Autoencoders with Smooth Robust Latent Encoding
- An Undetectable Watermark for Generative Image Models
- DiffuseTrace: A Transparent and Flexible Watermarking Scheme for Latent Diffusion Model
- CLUE-MARK: Watermarking Diffusion Models using CLWE
- Tree-Ring Watermarks: Fingerprints for Diffusion Images that are Invisible and Robust
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs