CoverLock

Official checkpoints for Residual Transferability in Neural Image Watermarking.

Project page · GitHub · Paper

CoverLock is a plug-and-play defense that binds a binary watermark payload to its cover image. It derives a robust image-dependent code from frozen DINOv2 features and applies that code to the payload through XOR. The original watermark encoder and decoder remain frozen and unmodified.

Checkpoints

File DINOv2 backbone Feature layer Size
coverlock_s.pt ViT-S/14 11 3.2 MB
coverlock_b.pt ViT-B/14 11 4.7 MB
coverlock_l.pt ViT-L/14 23 5.8 MB
coverlock_g.pt ViT-G/14 39 7.9 MB

The checkpoint contains the lightweight CoverLock head and its configuration. The corresponding frozen DINOv2 backbone is downloaded through PyTorch Hub on first use.

Installation

pip install "git+https://github.com/holdrain/Coverlock.git"
pip install huggingface_hub

Load a checkpoint

from huggingface_hub import hf_hub_download
from coverlock import CoverLock

checkpoint = hf_hub_download(
    repo_id="zipingdong123/Coverlock",
    filename="coverlock_s.pt",
)

model = CoverLock.from_checkpoint(checkpoint, device="cuda")

Use coverlock_b.pt, coverlock_l.pt, or coverlock_g.pt to select a larger DINOv2 backbone.

Bind and recover a watermark payload

CoverLock wraps an existing binary watermark codec. The sender binds the message to the cover image before embedding; the receiver repeats the operation after watermark decoding.

import torch

# Sender
cover_code = model.encode_pil(cover_image)
bound_message = torch.logical_xor(message.bool(), cover_code)
watermarked_image = watermark_encoder(cover_image, bound_message)

# Receiver
decoded_message = watermark_decoder(received_image)
received_code = model.encode_pil(received_image)
recovered_message = torch.logical_xor(decoded_message, received_code)

message, bound_message, and decoded_message must have the same bit length. For watermark codecs with fewer than 256 message bits, use the same fixed subset of CoverLock bits at the sender and receiver.

Command line

After installing the package, generate an image-conditioned code with:

coverlock encode \
  --checkpoint coverlock_s.pt \
  --image path/to/image.jpg \
  --device cuda

Intended use

CoverLock is intended for research on neural image watermarking, residual-transfer forgery, and content-bound payloads. It is a wrapper around an existing binary watermark encoder and decoder, not a standalone watermark codec.

Citation

@misc{dong2026residual,
  title         = {Residual Transferability in Neural Image Watermarking},
  author        = {Dong, Ziping and Li, Qi and Wang, Xinchao},
  year          = {2026},
  eprint        = {2609.32241},
  archivePrefix = {arXiv},
  primaryClass  = {cs.CR},
  url           = {https://arxiv.org/abs/2609.32241}
}
Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Paper for zipingdong123/Coverlock