FARI: Robust One-Step Inversion for Watermarking in Diffusion Models
Jindong Yang, Han Fang, Weiming Zhang, Nenghai Yu, Kejiang Chen
cs.CR, cs.AI
Submitted: 2026-07-29
Comments: Accepted by ICLR 2026
Code: https://github.com/0xD009/FARI
License: http://creativecommons.org/licenses/by/4.0/
The gist: Inversion-based watermarking is a promising approach to authenticate diffusion-generated images, yet practical use is bottlenecked by inversion that is both slow and error-prone.
Terminology
Abstract
Inversion-based watermarking is a promising approach to authenticate diffusion-generated images, yet practical use is bottlenecked by inversion that is both slow and error-prone. While the primary challenge in the watermarking setting is robustness against external distortions, existing approaches over-optimize internal truncation error, and because that error scales with the sampler step size, they are inherently confined to high-NFE (number of function evaluations) regimes that cannot meet the dual demands of speed and robustness. In this work, we have two key observations: (i) the inversion trajectory has markedly lower curvature than the forward generation path does, making it highly compressible and amenable to low-NFE approximation; and (ii) in inversion for watermark verification, the trade-off between speed and truncation error is less critical, since external distortions dominate the error. A faster inverter provides a dual benefit: it is not only more efficient, but it also enables end-to-end adversarial training to directly target robustness, a task that is computationally prohibitive for the original, lengthy inversion trajectories. Building on this, we propose FARI (Fast Asymmetric Robust Inversion), a one-step inversion framework paired with lightweight adversarial LoRA fine-tuning of the denoiser for watermark extraction. While consolidation slightly increases internal error, FARI delivers large gains in both speed and robustness: with approximately 20 minutes of fine-tuning on a single NVIDIA RTX A6000 GPU, it surpasses 50-step DDIM inversion on watermark-verification robustness while dramatically reducing inference time. Code and pretrained models are available at https://github.com/0xD009/FARI.
Sources
- Variational image compression with a scale hyperprior
- An Undetectable Watermark for Generative Image Models
- Prompt-to-Prompt Image Editing with Cross Attention Control
- Classifier-Free Diffusion Guidance
- VideoShield: Regulating Diffusion-based Video Generation Models via Watermarking
- Direct Inversion: Boosting Diffusion-based Editing with 3 Lines of Code
- GaussMarker: Robust Dual-Domain Watermark for Diffusion Models
- Pseudo Numerical Methods for Diffusion Models on Manifolds
- DPM-Solver++: Fast Solver for Guided Sampling of Diffusion Probabilistic Models
- Leveraging Optimization for Adaptive Attacks on Image Watermarks
- LCM-LoRA: A Universal Stable-Diffusion Acceleration Module
- Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models
- SDXL: Improving Latent Diffusion Models for High-Resolution Image Synthesis
- Progressive Distillation for Fast Sampling of Diffusion Models
- Lightning-Fast Image Inversion and Editing for Text-to-Image Diffusion Models
- Score-Based Generative Modeling through Stochastic Differential Equations
- Consistency Models
- There and Back Again: On the relation between Noise and Image Inversions in Diffusion Models
- Tree-Ring Watermarks: Fingerprints for Diffusion Images that are Invisible and Robust
- Gaussian Shading++: Rethinking the Realistic Deployment Challenge of Performance-Lossless Image Watermark for Diffusion Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs