Meta # Content Seal ### State-of-the-Art Invisible Watermarking [![Website](https://img.shields.io/badge/Website-Visit-blue)](https://facebookresearch.github.io/meta-seal) [![License: MIT](https://img.shields.io/badge/License-MIT-green)](LICENSE) **[Visit the Content Seal Website →](https://facebookresearch.github.io/content-seal)**
--- Content Seal is a comprehensive framework for invisible, robust watermarking across **all modalities** — audio, image, video, and text. It spans the entire generative AI lifecycle, from training data and inference to generated media, providing state-of-the-art tools for content provenance and authentication.
![Content Seal Overview](assets/banner_vid2.gif)
## Contents - [Post-Hoc Watermarking](#post-hoc-watermarking) - [In-Model and Generation-Time Watermarking](#in-model-and-generation-time-watermarking) - [Watermark Security](#watermark-security) - [License](#license) --- ## Post-Hoc Watermarking Watermarks applied **after content generation** by any model or system — model-agnostic and universal across all content types.
![Post-Hoc Watermarking](assets/2025-12-posthoc.gif)
### Content Seal for Images and Video Content Seal Image is deployed at scale for Muse Image with a custom proprietary implementation. We also provide open-source versions of our research models for images and video, readily available to download. | Research | Links | |:---|:---| | **Pixel Seal: Adversarial-Only Training for Invisible Image and Video Watermarking**
Flagship image & video watermarking model, SOTA in robustness and imperceptibility, built with a more stable adversarial-only training paradigm. | [![Paper](https://img.shields.io/badge/Paper-Meta_AI-0866FF?style=flat-square&logo=meta&logoColor=white)](https://ai.meta.com/research/publications/pixel-seal-adversarial-only-training-for-invisible-image-and-video-watermarking/) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/videoseal) | | **We Can Hide More Bits: The Unused Watermarking Capacity in Theory and in Practice**
Bigger model with 4× capacity boost to 1024 bits while preserving quality and robustness. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2510.12812) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/videoseal) | | **Video Seal: Open and Efficient Video Watermarking**
Extension of image watermarking models to video, resilient to editing and video codecs. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2412.09492) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/videoseal) [![Demo](https://img.shields.io/badge/Demo-Live-1877F2?style=flat-square&logo=meta&logoColor=white)](https://aidemos.meta.com/videoseal) | | **Watermark Anything with Localized Messages**
Embed (possibly multiple) localized watermarks into images; survives inpainting and splicing attacks. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2411.07231) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/watermark-anything) | | **Geometric Image Synchronization with Deep Watermarking**
Robust image synchronization, enabling reversal of geometric transformations applied to an image. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2509.15208) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/watermark-anything) | ### Content Seal for Audio | Research | Links | |:---|:---| | **Proactive Detection of Voice Cloning with Localized Watermarking**
Localized audio watermarking with sample-level detection and streaming support for real-time applications. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2401.17264) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/audioseal) | ### Content Seal for Text | Research | Links | |:---|:---| | **How Good is Post-Hoc Watermarking With Language Model Rephrasing?**
Comprehensive evaluation framework for post-hoc text watermarking with LLM rephrasing. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2512.16904) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/textseal) | --- ## In-Model and Generation-Time Watermarking Watermarks embedded **during content generation** by modifying model behavior or latent representations.
![In-Model Watermarking](assets/2025-12-inmodel.gif)
### Content Seal for Text | Research | Links | |:---|:---| | **TextSeal: A Localized LLM Watermark for Provenance & Distillation Protection**
SOTA LLM watermark with dual-key Gumbel-max sampling, entropy-weighted scoring, and multi-region localization. Distortion-free, preserves reasoning and benchmark performance, detectable when diluted in human text, radioactive through distillation. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2605.12456) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/textseal) | ### Content Seal for Image & Audio | Research | Links | |:---|:---| | **Learning to Watermark in the Latent Space of Generative Models**
Unified latent-space watermarking that enables 20× speedup over pixel methods and secures open-source models via in-model distillation. | [![Paper](https://img.shields.io/badge/Paper-Meta_AI-0866FF?style=flat-square&logo=meta&logoColor=white)](https://ai.meta.com/research/publications/distilling-latent-space-watermarkers-into-generative-image-models/) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/distseal) | | **The Stable Signature: Rooting Watermarks in Latent Diffusion Models**
Roots the watermark in the model's latent decoder for tracing the outputs of latent generative models. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2303.15435) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/stable_signature) | | **Watermarking Autoregressive Image Generation**
Watermarking for autoregressive image generation models. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2506.16349) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/wmar) | ### Radioactivity | Research | Links | |:---|:---| | **Watermarking Makes Language Models Radioactive**
Detects if a language model was trained on synthetic text by finding weak residuals of watermark signals in fine-tuned LLMs — high-confidence even when as little as 5% of training text is watermarked. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2402.14904) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/radioactive-watermark) | | **Detecting Benchmark Contamination Through Watermarking**
Watermarks benchmarks before release to detect if models were trained on test sets, using theoretically grounded statistical tests while preserving benchmark utility. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2502.17259) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/textseal) | --- ## Watermark Security Research on **adversarial attacks and defenses** for watermarking systems through red teaming.
![Security Demo](assets/2025-12-forger.gif)
| Research | Links | |:---|:---| | **Transferable Black-Box One-Shot Forging of Watermarks via Image Preference Models**
Black-box watermark forging using image preference models for red-teaming watermarking systems. | [![Paper](https://img.shields.io/badge/Paper-arXiv-b31b1b?style=flat-square&logo=arxiv&logoColor=white)](https://arxiv.org/abs/2510.20468) [![Code](https://img.shields.io/badge/Code-GitHub-181717?style=flat-square&logo=github&logoColor=white)](https://github.com/facebookresearch/videoseal/tree/main/wmforger) | --- ## License The code is licensed under an [MIT license](LICENSE).