SIGNAL

Source-Integrated Generative-content Attribution and Labeling

Watermarking, fingerprinting, deepfake detection, and provenance benchmarks, across all carriers.

About the workshop

Provenance at the source

The premise

Provenance has two sides. Post-hoc detection judges content after it circulates. Source-side marking embeds a recoverable signal at creation time and reads it back later. SIGNAL is about the second: marking as an engineering problem, measured honestly.

The mandate

The California AI Transparency Act, operative since August 2, 2026, requires generative providers to embed a latent disclosure that is permanent or extraordinarily difficult to remove. No benchmark defines that phrase. Making it measurable is what SIGNAL is organized around.

The gap

The research is currently split into separate literatures for image, audio, video, model, and sequence marking, even though the attacks generalize across carriers. SIGNAL treats them as one applied problem and brings the communities to one room.

Scope

Substrates we cover

Visual

Image and video watermarking, in-generation marking for diffusion models, robustness to compression, cropping, regeneration, and screenshot re-capture.

Audio and speech

Watermarking for TTS and voice cloning, survival under codecs, re-recording, and time-stretching.

Models and weights

Watermarking and fingerprinting neural networks, IP attribution, generator attribution from intrinsic artifacts, robustness to fine-tuning, distillation, and quantization.

Biological substrates

Marking DNA sequences and engineered organisms, encoding under mutation, recombination, and sequencing noise.

Adversarial

Watermark removal, forgery, and spoofing. The arms race as a first-class research object.

Cross-substrate theory

Unified capacity, robustness, and imperceptibility formulations. Whether a threat model or evaluation protocol transfers across carriers.

Systems and standards

C2PA and Content Credentials, interoperability, deployment at platform scale.

Benchmarks

Shared test suites, attack batteries, and reporting standards for robustness claims.

And beyond

The list above is a guide, not a fence. If your work touches watermarking, fingerprinting, provenance, or the benchmarks that measure them, in any carrier, it belongs here. When in doubt, submit or write to us.

Important dates

Timeline

All deadlines are 11:59 PM Anywhere on Earth unless stated otherwise.

  1. Aug 28, 2026 Submissions open Submit on OpenReview
  2. Oct 15, 2026 Submission deadline All tracks
  3. Oct 30, 2026 Author notification Decisions sent to all submitters
  4. Nov 20, 2026 Camera-ready due Archival papers, 11:59 PM Pacific Time
  5. Jan 4 or 5, 2027 Workshop Disney Springs, Buena Vista, Florida. Day TBA
Program

Agenda

Half day, in person. The agenda will be adjusted as accepted papers and speaker titles are confirmed.

5 minOpening: one problem, many carriers
30 minInvited talk IMarking biological substrates, from DNA storage to engineered organisms
40 minOral session IFour archival papers, 10 minutes each
20 minCoffee break and poster setup
30 minInvited talk IIWhat forensics can establish once a mark is gone
30 minEvaluation resultsWhat survived the common protocol, and what did not
40 minPoster sessionAll accepted papers. Attendee vote opens
35 minPanel: what can a watermark actually guarantee?
10 minClosing, award presentation, and next edition
Speakers

Invited speakers

Talks span the carriers the call covers, from visual media to biological substrates and the policy layer above them. The final lineup may be adjusted, and confirmed names are posted here with talk titles.

Confirmed

Zhong Wang

Lawrence Berkeley National Laboratory

On marking DNA, and what mutation-tolerant encoding demands that media channels do not.

Biological substrates
Confirmed

Jerry Chai

Stanford University

On how disclosure requirements are written, enforced, and assessed.

Policy
Invitations in progress

More speakers to be announced

We are inviting additional speakers on audio and speech, media forensics, and language models. Names and talk titles will be posted here as they confirm.

Organizers and program committee

Who is running this

The committee is still growing. If you would like to review, write to us.

Zhong Wang

Lawrence Berkeley National Laboratory

Staff Scientist and Genome Analysis Group Lead at the DOE Joint Genome Institute. Author of genomic foundation-model work including DNABERT-S and GenomeOcean.

Senior co-organizer · Biology

Fengchen Liu

Lawrence Berkeley National Laboratory

Works on artificial intelligence and image processing, watermarking, knowledge representation, and distributed computing at scale.

Organizer · Visual track

Guang Yang

Phi Lab Foundation · UCLA

Watermarking, content authenticity, and deepfake detection, with agent-based simulation of how generative media propagates online.

Organizer · Primary contact

Li Lei

Syngenta

Computational biologist building pipelines that read signal out of noisy sequencing data, where mutation corrupts the record as no media channel does.

Program committee · Sequences

Jerry Chai

Stanford University

Research Fellow and instructor of CS 389: Internet Censorship. Platform governance and the US regulatory landscape for synthetic media.

Program committee · Policy

Qian Zhang

College of Charleston

Human factors and the usability of disclosures. How a provenance signal is read, trusted, and acted on by the people it is meant to protect.

Program committee · Human factors
Contact

Submissions close October 15, 2026

For questions about submissions, the awards, or the workshop generally, write to the organizing committee.

SIGNAL is organized with support from Phi Lab Foundation, a non-profit for public-benefit AI research and open-source ecosystems, which funds the awards, speaker travel, and long-term hosting of all workshop artifacts.