Papers › Watermark Anything with Localized Messages
Watermark Anything with Localized Messages
Tom Sander, Pierre Fernandez, Alain Durmus, Teddy Furon, Matthijs Douze
Image watermarking methods are not tailored to handle small watermarked areas. This restricts applications in real-world scenarios where parts of the image may come from different sources or have been edited. We introduce a deep-learning model for localized image watermarking, dubbed the Watermark Anything Model (WAM). The WAM embedder imperceptibly modifies the input image, while the extractor segments the received image into watermarked and non-watermarked areas and recovers one or several hidden messages from the areas found to be watermarked. The models are jointly trained at low resolution and without perceptual constraints, then post-trained for imperceptibility and multiple watermarks. Experiments show that WAM is competitive with state-of-the art methods in terms of imperceptibility and robustness, especially against inpainting and splicing, even on high-resolution images. Moreover, it offers new capabilities: WAM can locate watermarked areas in spliced images and extract distinct 32-bit messages with less than 1 bit error from multiple small regions - no larger than 10% of the image surface - even for small 256×256 images.
In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.
For agents, Syntology's MCP tool lists every function and class Syntology harvested from this paper and whether it ran (how to connect): get_harvested_code_for_paper(arxiv_id="2411.07231")
Code
Syntology Ran 34 of 49 code samples harvested from 2 repositories linked to this paper; 15 have no recorded run. Of those that ran: 4 ran · our draft was wrong; 2 ran · fixture could not drive it; 28 ran with no contract checked.
By repository: official repository: 34 samples from 1 repository, 22 ran; found in paper text by Syntology: 15 samples from 1 repository, 12 ran. The run record, sample by sample. “Ran” means executed on a synthesized input, not that the code is correct or reproduces the paper.
Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.
Code Syntology ran Syntology
49 samples harvested; 34 ran; 0 honoured the contract we drafted; 15 have no recorded run. Read from Syntology's graph 2026-09-24; that is when this build read the record, not when the samples ran.
Licence: 0 of the 49 samples are pointer only, meaning Syntology does not serve that copy's text. This page shows no code text for any sample; each one links to its file in the repository.
Harvested from 2 repositories linked to this paper, official or community; each sample names its own and says which. “Ran” means the sample executed on a synthesized input. It does not mean the output is correct, and nothing here reproduces the paper's results. “Honoured” and “violated” refer to a contract Syntology drafted from the code itself; “our draft was wrong” and “fixture could not drive it” are failures of Syntology's instrument, not of the code.
Each sample ends with its code_sha256, Syntology's identity for that exact code. An agent fetches the stored sample with Syntology's MCP tool get_code(code_sha256="…") (how to connect); click an identity to copy that call.
Repository labels, per sample. official repository: The archive marks this repository official for the paper. named in the paper: The archive records that the paper mentions this repository; it is not marked official. community (archive-listed): In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper. found in paper text by Syntology: Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted. community: Not in the archive's code links for this paper; a community repository Syntology harvested. Samples from a repository marked official are listed first. Licence labels name the repository's licence as recorded at harvest. “Pointer only” means Syntology does not serve that copy's text, for one of four reasons: no licence file was found; the licence was not identified; the licence is recorded as permissive but that copy's record is not marked cleared; or the licence is outside the permissive list Syntology serves text under (MIT, Apache-2.0, BSD and similar). Some licences outside that list permit redistribution, such as WTFPL, and GPL-3.0 under its conditions; they are simply not on the list. Hover a licence label for the reason. File links open the file on GitHub at the default branch, which may have changed since the harvest.
80c21d2438a32b0e · report
e9eafb1566e6b410 · report
01cf303cd45363e0 · report
06b45d2bcb7006fd · report
0586a3f60f44d1f6 · report
e3ec9af8c9ef9bee · report
843dfd652b76d05e · report
45df3aed2dab3bf2 · report
bcb4b3ed6a29fdd0 · report
9bf49095b19f1774 · report
8b41e1fbee5d7c00 · report
22b2c33174652dc9 · report
8122ac142e3190b1 · report
78f1137a7dc7ad7f · report
3d789e9b974a7cdf · report
1f79e4607cb770db · report
07b001f953998cdf · report
b3a188c9eac7c269 · report
d6cd467d5838c3d0 · report
3fb53df7c3ecd86c · report
f174810f10e50f60 · report
d7e21a6d2678b40a · report
7862f045dd0fd872 · report
615d578f9886ba11 · report
529c6fe4a443b596 · report
d3878cd75bb34bcc · report
219f742447bb98ef · report
195434aa62fd8554 · report
6f71f109c486291d · report
01ba359cc74e2aaa · report
9b9166a37f2ebce0 · report
e27c0cf92043cd20 · report
0769e3294c73148e · report
49e8f05f9263440b · report
5802352d3cfc6757 · report
883a16a7d30049e6 · report
9654be1ceb1764d3 · report
9a681920adecc1a9 · report
3460d3a7d1d7d183 · report
66f5d3721ebaec97 · report
6786197ec4189fdc · report
51002caac8ee78d2 · report
7413418e45686eef · report
b67152b806ff0b3b · report
fdc644eb68bfe341 · report
56ce4c3dada95575 · report
b2ce99e0ce1fe547 · report
916d54931038c869 · report
3f1b2dec311a2e80 · report
Results from the paper archive 2025-07-28
No leaderboard rows for this paper in the archive.
Methods
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections