CoverLock
Official checkpoints for Residual Transferability in Neural Image Watermarking.
Project page · GitHub · Paper
CoverLock is a plug-and-play defense that binds a binary watermark payload to its cover image. It derives a robust image-dependent code from frozen DINOv2 features and applies that code to the payload through XOR. The original watermark encoder and decoder remain frozen and unmodified.
Checkpoints
| File | DINOv2 backbone | Feature layer | Size |
|---|---|---|---|
coverlock_s.pt |
ViT-S/14 | 11 | 3.2 MB |
coverlock_b.pt |
ViT-B/14 | 11 | 4.7 MB |
coverlock_l.pt |
ViT-L/14 | 23 | 5.8 MB |
coverlock_g.pt |
ViT-G/14 | 39 | 7.9 MB |
The checkpoint contains the lightweight CoverLock head and its configuration. The corresponding frozen DINOv2 backbone is downloaded through PyTorch Hub on first use.
Installation
pip install "git+https://github.com/holdrain/Coverlock.git"
pip install huggingface_hub
Load a checkpoint
from huggingface_hub import hf_hub_download
from coverlock import CoverLock
checkpoint = hf_hub_download(
repo_id="zipingdong123/Coverlock",
filename="coverlock_s.pt",
)
model = CoverLock.from_checkpoint(checkpoint, device="cuda")
Use coverlock_b.pt, coverlock_l.pt, or coverlock_g.pt to select a larger DINOv2 backbone.
Bind and recover a watermark payload
CoverLock wraps an existing binary watermark codec. The sender binds the message to the cover image before embedding; the receiver repeats the operation after watermark decoding.
import torch
# Sender
cover_code = model.encode_pil(cover_image)
bound_message = torch.logical_xor(message.bool(), cover_code)
watermarked_image = watermark_encoder(cover_image, bound_message)
# Receiver
decoded_message = watermark_decoder(received_image)
received_code = model.encode_pil(received_image)
recovered_message = torch.logical_xor(decoded_message, received_code)
message, bound_message, and decoded_message must have the same bit length. For watermark codecs with fewer than 256 message bits, use the same fixed subset of CoverLock bits at the sender and receiver.
Command line
After installing the package, generate an image-conditioned code with:
coverlock encode \
--checkpoint coverlock_s.pt \
--image path/to/image.jpg \
--device cuda
Intended use
CoverLock is intended for research on neural image watermarking, residual-transfer forgery, and content-bound payloads. It is a wrapper around an existing binary watermark encoder and decoder, not a standalone watermark codec.
Citation
@misc{dong2026residual,
title = {Residual Transferability in Neural Image Watermarking},
author = {Dong, Ziping and Li, Qi and Wang, Xinchao},
year = {2026},
eprint = {2609.32241},
archivePrefix = {arXiv},
primaryClass = {cs.CR},
url = {https://arxiv.org/abs/2609.32241}
}