A Comprehensive Survey of Watermarking, Fingerprinting, and Blockchain-Based Authentication for Provenance Verification of AI-Generated Images

Authors

  • Sriharsha S. H.
  • Srikanth N. A. S.
  • Samarth Jayant
  • Rohan A. B.
  • Mahesh Kumar N

Keywords:

AI-generated images, Blockchain authentication, Digital watermarking, Perceptual hashing, Provenance verification, Synthetic media detection

Abstract

The rapid growth of diffusion models and generative adversarial networks has increased the availability of AI-generated images and intensified the need to verify their provenance, including origin, authenticity, and modification history. This survey reviews 20 works published from 2023 to 2026 and organizes them into four primary provenance approaches: digital watermarking, perceptual hashing/fingerprinting, blockchain-anchored registries, and synthetic-media detection, while also examining recent watermark-removal and forgery attacks. The review covers diffusion-native methods such as Tree-Ring Watermarks and Stable Signature, post-hoc methods such as InvisMark and Watermark Anything, perceptual-fingerprinting approaches such as DinoHash, and blockchain-based registry mechanisms. It further analyzes attacks including MarkSweep, Warfare, the Next-Frame Prediction Attack, and boundary-leakage attacks. A recurring limitation is that provenance verification is often reduced to an authenticity or match decision, even when the underlying watermark can carry multi-bit information; this limits direct assessment of the type and severity of image modifications. Other challenges include cross-architecture generalization, spatial redundancy, inconsistent threat models, and the absence of a universally adopted evaluation benchmark. The survey synthesizes these findings and identifies research directions for building more robust, interpretable, and practically deployable AI image provenance systems.

References

Y. Zou et al., “Survey on AI-generated media detection: From non-MLLM to MLLM,” arXiv, Feb. 2025.

R. Xu et al., “InvisMark: Invisible and robust watermarking for AI-generated image provenance,” 2025 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV), Tucson, AZ, USA, 2025, pp. 909–918.

Y. Wen, J. Kirchenbauer, J. Geiping, and T. Goldstein, “Tree-Ring watermarks: Fingerprints for diffusion images that are invisible and robust,” arXiv, May 2023.

P. Fernandez, G. Couairon, H. Jégou, M. Douze, and T. Furon, “The stable signature: Rooting watermarks in latent diffusion models,” arXiv, Mar. 2023.

X. Zhao et al., “SoK: Watermarking for AI-generated content,” 2025 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 2025, pp. 2621–2639.

A. Mohit, B. Aggarwal, and C. Gondhalekar, “Provenance verification of AI-generated images via a perceptual hash registry anchored on blockchain,” arXiv, Feb. 2026.

J. Cao, Z. Zhang, Q. Li, and J. Ni, “MarkSweep: A no-box removal attack on AI-generated image watermarking via noise intensification and frequency-aware denoising,” arXiv, Feb. 2026.

G. Li et al., “Warfare: Breaking the watermark protection of AI-generated content,” arXiv, Sept. 2023.

H. Qiu, Z. Wang, M. Zhang, X. Zhang, X. You, and M. Yang, “The future unmarked: Watermark removal in AI-generated images via next-frame prediction,” in Advances in Neural Information Processing Systems 38, 2025.

G. Li, Y. Chen, J. Zhang, J. Li, S. Guo, and T. Zhang, “Warfare:Breaking the Watermark Protection of AI-Generated Content,” arXiv (Cornell University), Jan. 2023.

B. Chandra, J. Dunietz, K. Roberts, Y. Lee, P. Fontana, and G. Awad, “Reducing risks posed by synthetic content: An overview of technical approaches to digital content transparency,” NIST AI 100-4, National Institute of Standards and Technology, Gaithersburg, MD, USA, Nov. 2024.

S. Singhi, A. Yadav, A. Gupta, S. Ebrahimi, and P. Hassanizadeh, “Provenance detection for AI-generated images: Combining perceptual hashing, homomorphic encryption, and AI detection models,” arXiv, Mar. 2025.

K. Arabi, R. T. Witter, C. Hegde and N. Cohen, “SEAL: Semantic Aware Image Watermarking,” 2025 IEEE/CVF International Conference on Computer Vision (ICCV), Honolulu, HI, USA, 2025, pp. 16196–16205.

T. Sander, P. Fernandez, A. O. Durmus, T. Furon, and M. Douze, “Watermark anything with localized messages,” in Proceedings of International Conference on Learning Representations, 2025.

X. Li and R. Xu, “A comprehensive survey of watermarking techniques for copyright protection and integrity verification on DNNs and generative models,” Discover Applied Sciences, vol. 8, Mar. 2026.

H. Luo, L. Li, and J. Li, “Digital watermarking technology for AI-generated images: A survey,” Mathematics, vol. 13, no. 4, Feb. 2025.

J. Cao, Q. Li, Z. Zhang, J. Ni, and R. Lu, “Secure and robust watermarking for AI-generated images: A comprehensive survey,” arXiv, Sept. 2025.

P. Fernandez, “Watermarking across modalities for content tracing and generative AI,” arXiv, Feb. 2025.

M. Ding et al., “A technical report on ‘erasing the invisible’: The 2024 NeurIPS competition on stress testing image watermarks,” in Advances in Neural Information Processing Systems 38, 2025, pp. 16168–16199.

M. Bistroń, J. M. Żurada, and Z. Piotrowski, “Deep learning for image watermarking: A comprehensive review and analysis of techniques, challenges, and applications,” Sensors, vol. 26, no. 2, Jan. 2026.

Published

2026-09-21

How to Cite

Sriharsha S. H., Srikanth N. A. S., Samarth Jayant, Rohan A. B., & Mahesh Kumar N. (2026). A Comprehensive Survey of Watermarking, Fingerprinting, and Blockchain-Based Authentication for Provenance Verification of AI-Generated Images. Journal of Information Security System and Cyber Criminology Research, 1–12. Retrieved from https://matjournals.net/engineering/index.php/JoISSCCR/article/view/4151