Tree-Ring Watermark: Invisible Robust Fingerprints of Diffusion Images

In order to prevent harm from AI-generated content and trace copyright, watermarking outputs of generative models is crucial. A new technique called Tree-Ring Watermarking has been developed, which fingerprints diffusion model outputs in a way that is invisible to humans. Unlike other methods that modify images after sampling, Tree-Ring Watermarking subtly influences the entire process of sampling, embedding structured patterns into the initial noise vector. This allows for detection of the watermark signal by inverting the diffusion process to retrieve the noise vector, which is then checked for the embedded signal. The technique can be easily applied to arbitrary diffusion models, including text-conditioned Stable Diffusion, with negligible loss in FID.

