
# Content Seal
### State-of-the-Art Invisible Watermarking
[](https://facebookresearch.github.io/meta-seal)
[](LICENSE)
**[Visit the Content Seal Website →](https://facebookresearch.github.io/content-seal)**
---
Content Seal is a comprehensive framework for invisible, robust watermarking across **all modalities** — audio, image, video, and text. It spans the entire generative AI lifecycle, from training data and inference to generated media, providing state-of-the-art tools for content provenance and authentication.

## Contents
- [Post-Hoc Watermarking](#post-hoc-watermarking)
- [In-Model and Generation-Time Watermarking](#in-model-and-generation-time-watermarking)
- [Watermark Security](#watermark-security)
- [License](#license)
---
## Post-Hoc Watermarking
Watermarks applied **after content generation** by any model or system — model-agnostic and universal across all content types.

### Content Seal for Images and Video
Content Seal Image is deployed at scale for Muse Image with a custom proprietary implementation. We also provide open-source versions of our research models for images and video, readily available to download.
| Research | Links |
|:---|:---|
| **Pixel Seal: Adversarial-Only Training for Invisible Image and Video Watermarking**
Flagship image & video watermarking model, SOTA in robustness and imperceptibility, built with a more stable adversarial-only training paradigm. | [](https://ai.meta.com/research/publications/pixel-seal-adversarial-only-training-for-invisible-image-and-video-watermarking/) [](https://github.com/facebookresearch/videoseal) |
| **We Can Hide More Bits: The Unused Watermarking Capacity in Theory and in Practice**
Bigger model with 4× capacity boost to 1024 bits while preserving quality and robustness. | [](https://arxiv.org/abs/2510.12812) [](https://github.com/facebookresearch/videoseal) |
| **Video Seal: Open and Efficient Video Watermarking**
Extension of image watermarking models to video, resilient to editing and video codecs. | [](https://arxiv.org/abs/2412.09492) [](https://github.com/facebookresearch/videoseal) [](https://aidemos.meta.com/videoseal) |
| **Watermark Anything with Localized Messages**
Embed (possibly multiple) localized watermarks into images; survives inpainting and splicing attacks. | [](https://arxiv.org/abs/2411.07231) [](https://github.com/facebookresearch/watermark-anything) |
| **Geometric Image Synchronization with Deep Watermarking**
Robust image synchronization, enabling reversal of geometric transformations applied to an image. | [](https://arxiv.org/abs/2509.15208) [](https://github.com/facebookresearch/watermark-anything) |
### Content Seal for Audio
| Research | Links |
|:---|:---|
| **Proactive Detection of Voice Cloning with Localized Watermarking**
Localized audio watermarking with sample-level detection and streaming support for real-time applications. | [](https://arxiv.org/abs/2401.17264) [](https://github.com/facebookresearch/audioseal) |
### Content Seal for Text
| Research | Links |
|:---|:---|
| **How Good is Post-Hoc Watermarking With Language Model Rephrasing?**
Comprehensive evaluation framework for post-hoc text watermarking with LLM rephrasing. | [](https://arxiv.org/abs/2512.16904) [](https://github.com/facebookresearch/textseal) |
---
## In-Model and Generation-Time Watermarking
Watermarks embedded **during content generation** by modifying model behavior or latent representations.

### Content Seal for Text
| Research | Links |
|:---|:---|
| **TextSeal: A Localized LLM Watermark for Provenance & Distillation Protection**
SOTA LLM watermark with dual-key Gumbel-max sampling, entropy-weighted scoring, and multi-region localization. Distortion-free, preserves reasoning and benchmark performance, detectable when diluted in human text, radioactive through distillation. | [](https://arxiv.org/abs/2605.12456) [](https://github.com/facebookresearch/textseal) |
### Content Seal for Image & Audio
| Research | Links |
|:---|:---|
| **Learning to Watermark in the Latent Space of Generative Models**
Unified latent-space watermarking that enables 20× speedup over pixel methods and secures open-source models via in-model distillation. | [](https://ai.meta.com/research/publications/distilling-latent-space-watermarkers-into-generative-image-models/) [](https://github.com/facebookresearch/distseal) |
| **The Stable Signature: Rooting Watermarks in Latent Diffusion Models**
Roots the watermark in the model's latent decoder for tracing the outputs of latent generative models. | [](https://arxiv.org/abs/2303.15435) [](https://github.com/facebookresearch/stable_signature) |
| **Watermarking Autoregressive Image Generation**
Watermarking for autoregressive image generation models. | [](https://arxiv.org/abs/2506.16349) [](https://github.com/facebookresearch/wmar) |
### Radioactivity
| Research | Links |
|:---|:---|
| **Watermarking Makes Language Models Radioactive**
Detects if a language model was trained on synthetic text by finding weak residuals of watermark signals in fine-tuned LLMs — high-confidence even when as little as 5% of training text is watermarked. | [](https://arxiv.org/abs/2402.14904) [](https://github.com/facebookresearch/radioactive-watermark) |
| **Detecting Benchmark Contamination Through Watermarking**
Watermarks benchmarks before release to detect if models were trained on test sets, using theoretically grounded statistical tests while preserving benchmark utility. | [](https://arxiv.org/abs/2502.17259) [](https://github.com/facebookresearch/textseal) |
---
## Watermark Security
Research on **adversarial attacks and defenses** for watermarking systems through red teaming.

| Research | Links |
|:---|:---|
| **Transferable Black-Box One-Shot Forging of Watermarks via Image Preference Models**
Black-box watermark forging using image preference models for red-teaming watermarking systems. | [](https://arxiv.org/abs/2510.20468) [](https://github.com/facebookresearch/videoseal/tree/main/wmforger) |
---
## License
The code is licensed under an [MIT license](LICENSE).