Breaking Semantic-Aware Watermarks via LLM-Guided Coherence-Preserving Semantic Injection

Generative images have proliferated on Web platforms in social media and online copyright distribution scenarios, and semantic watermarking has increasingly been integrated into diffusion models to support reliable provenance tracking and forgery prevention for web content. Traditional noise-layer-based watermarking, however, remains vulnerable to inversion attacks that can recover embedded signals. To mitigate this, recent content-aware semantic watermarking schemes bind watermark signals to high-level image semantics, constraining local edits that would otherwise disrupt global coherence. Yet, large language models (LLMs) possess structured reasoning capabilities that enable targeted exploration of semantic spaces, allowing locally fine-grained but globally coherent semantic alterations that invalidate such bindings. To expose this overlooked vulnerability, we introduce a Coherence-Preserving Semantic Injection (CSI) attack that leverages LLM-guided semantic manipulation under embedding-space similarity constraints. This alignment enforces visual-semantic consistency while selectively perturbing watermark-relevant semantics, ultimately inducing detector misclassification. Extensive empirical results show that CSI consistently outperforms prevailing attack baselines against content-aware semantic watermarking, revealing a fundamental security weakness of current semantic watermark designs when confronted with LLM-driven semantic perturbations.

Paper

References (12)

052025.ForgingandRemovingLatent-NoiseDiffusionWatermarksUsingaSingle Image2025 · arXiv preprint
062024. HiddenintheNoise: Two-Stage Robust Watermarking for Images2024 · arXiv preprint
07GANsTrainedbyaTwoTime-ScaleUpdateRuleConverge to a Local Nash Equilibrium2018 · arXiv
082023. Diffusion Models: A Comprehensive Survey of Methods and ApplicationsComput. Surveys
092023. Large language models as optimizersThe Twelfth International Conference on Learning Representations
102025. Or-llm-agent: Automating modeling and solving of operations research optimization problem with reasoning large language modelarXiv
112024. Stable-diffusion-promptshuggingface.co/ datasets/Gustavosta/Stable-Diffusion-Prompts
122025. SEAL: Semantic-Aware Image WatermarkingProceedings of the IEEE/CVF International Conference on Computer Vision

Similar papers

© 2026 NYSGPT2525 LLC