Abstract

Text-to-image diffusion models enable data-efficient "mimicry" attacks, wherein adversaries fine-tune the model on a handful of public photos to synthesize convincing forgeries of a target individual. A common countermeasure is to embed imperceptible, low-energy watermarks, yet recent studies show these signatures are brittle: modest post-processing or lightweight adversarial perturbations readily suppress detection, exposing a fundamental tension between imperceptibility and robustness. We introduce FeatMark, a watermarking framework that shifts from pixel-level, energy-starved perturbations to inconspicuous semantic features: small, scene-consistent micro-features that remain natural to humans while providing a stronger, machine-verifiable provenance signal. FeatMark builds domain-specific feature banks that encode each watermark as a compact concept program, pairing open-vocabulary semantic cues with reliable edit regions and instruction templates. It then automatically selects features that are both feasible and executable and injects them through modular, mask-guided concept editing, yielding highly localized, scene-consistent micro-edits that are difficult to perceive. We conduct extensive experiments across VGGFace2, CelebA-HQ, and WikiArt, evaluating against 10 strong watermark removal/purification attacks (including regeneration-style purification) and several bespoke adaptive attacks tailored to FeatMark, to assess perceptual fidelity, watermark detection accuracy, and robustness. We further demonstrate FeatMark's extensibility to video mimicry attacks. The results show FeatMark remains virtually impervious, withstanding all evaluated attacks with negligible bit-accuracy and fidelity degradation.

Keywords

Subject

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Li, H., Sun, R., Ye, Q., Zhao, B. Z. H., Xiao, Y., Xue, J., & Hu, H. (2026). FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models. https://omanscience.com/en/articles/featmark-feature-level-watermark-protection-against-mimicry-attacks-with-diffusion-models

MLA 9

Li, Haoyang, et al. "FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models." https://omanscience.com/en/articles/featmark-feature-level-watermark-protection-against-mimicry-attacks-with-diffusion-models.

Chicago (author–date)

Li, Haoyang, Ruoxi Sun, Qingqing Ye, Benjamin Zi Hao Zhao, Yaxin Xiao, Jason Xue, and Haibo Hu. 2026. "FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models." https://omanscience.com/en/articles/featmark-feature-level-watermark-protection-against-mimicry-attacks-with-diffusion-models.

Harvard

Li, H., Sun, R., Ye, Q., Zhao, B. Z. H., Xiao, Y., Xue, J. and Hu, H. (2026) 'FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models', Available at: https://omanscience.com/en/articles/featmark-feature-level-watermark-protection-against-mimicry-attacks-with-diffusion-models.

Vancouver

Li H, Sun R, Ye Q, Zhao BZH, Xiao Y, Xue J, et al. FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models. https://omanscience.com/en/articles/featmark-feature-level-watermark-protection-against-mimicry-attacks-with-diffusion-models

IEEE

H. Li, R. Sun, Q. Ye, B. Z. H. Zhao, Y. Xiao, J. Xue, and H. Hu, "FeatMark: Feature-level Watermark Protection against Mimicry Attacks with Diffusion Models," https://omanscience.com/en/articles/featmark-feature-level-watermark-protection-against-mimicry-attacks-with-diffusion-models.