Study Finds AI Image Watermarks Can Survive Retraining, Though Resilience Varies
Researchers evaluated how imperceptible image watermarks endure across generative model iterations as developers seek methods to prevent model collapse.

Imperceptible watermarks embedded in artificial intelligence-generated images can survive when a new generative model is trained on those outputs, though their persistence varies widely depending on watermark design and model architecture, according to research presented at the ACM Workshop on Information Hiding and Multimedia Security (IH&MMSec 26) in Florence.
The paper, titled "Watermark Degradation Across Model Iterations," was authored by Michel Meintz of the SprintML Lab at the CISPA Helmholtz Center for Information Security and reported by TechXplore (https://techxplore.com/news/2026-10-ai-image-watermarks-survive-durability.html). The findings address an emerging risk for generative AI developers: model collapse, a progressive degradation in model output quality caused by repeatedly training algorithms on uncurated synthetic data scraped from the web.
To test whether watermarks can verify if a downstream model was trained on synthetic material, researchers used a two-step experimental framework. The team first generated synthetic images embedded with invisible watermarks, then used those images to train a secondary model. After training, researchers generated new outputs from the secondary model and tested whether the original watermark signal remained detectable.
The study evaluated four watermarking approaches—TrustMark, StableSignature, TreeRing, and BitMark—across both diffusion models and autoregressive image architectures. Rather than inspecting individual images in isolation, the researchers performed statistical analyses across image datasets to measure signal retention.
Persistence varied significantly across configurations. While some watermarking techniques lost their detectable signal after a single training cycle, others endured. BitMark, developed by SprintML, proved particularly resilient in testing on the Infinity-2B model, where researchers reliably detected the watermark signal even when marked images comprised only 1% of the training dataset.
The research also highlighted practical limits to cross-industry synthetic data filtering. Because commercial developers currently employ divergent watermarking schemes, one provider cannot readily identify synthetic data carrying another company's proprietary watermark. Meintz noted that establishing a unified industry standard remains difficult due to differing corporate requirements and rapid technical evolution.
Meintz plans to extend BitMark beyond the Infinity architecture to other model families and investigate stronger watermark signals that would allow detection in a single generated image rather than requiring statistical analysis across an entire dataset.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.

