The paper introduces RAIN, a lightweight, prompt‑free extractor for semantic watermarks in diffusion models. By decomposing the endpoint recovery into an image‑like anchor and a noise‑oriented residual, RAIN avoids iterative inversion and reduces the computational cost compared to existing one‑step methods. The approach leverages extended flow matching and conditional regression to recover a useful noise statistic near the high‑SNR image endpoint, enabling efficient one‑step extraction.
By Zilai Li
DRIFT is a black‑box attack that removes diffusion watermarks by deflecting the generative trajectory. It combines partial forward diffusion with stochastic reverse resampling to limit the source information available to a fixed‑depth recovery pipeline and to explore alternative noise‑driven paths. Across nine watermarks, DRIFT achieves 98–100% success while preserving image quality, without requiring secret keys, verifier internals, or per‑image gradient optimization.
By Rui Bao, Zheng Gao, Xiaoyu Li, Xiaoyan Feng, Yang Song, Jiaojiao Jiang
DRIFT is a black‑box attack that removes diffusion watermarks by combining partial forward diffusion with stochastic reverse resampling. It limits the source information available to a fixed‑depth recovery pipeline and uses stochastic reversal to explore alternative noise‑driven paths, refining fidelity only on updates rejected by the same verifier. Across nine watermarks, DRIFT achieves 98–100% attack success and the best image quality without requiring secret keys, verifier internals, or per‑image gradient optimization.
The paper introduces the first systematic robustness benchmark for local invisible image watermarking, evaluating five methods across 55 image transformations that include signal distortions, coordinate misalignments, indirect local edits, and direct watermark edits. Results show that all methods are vulnerable to some transformation, with MaskWM achieving the best payload recovery and localization but at the cost of image quality. The study highlights that robustness varies strongly with transformation type, especially noting that geometric misalignment and generative local edits can completely disrupt payload recovery.
By Kai Yao, Bence Szil\'agyi, Sebesty\'en Kamp, M\'at\'e Po\'or, M\'at\'e Szilveszter, Matyas K. Zsoldos, Marc Juarez
arXiv:2608. 10166v1 Announce Type: cross Abstract: Digital watermarking has emerged as a critical technique for provenance and copyright attribution in AI-generated imagery, yet its robustness against realistic, model-agnostic removal attacks remains poorly explored.
By Jie Cao, Qi Li, Zelin Zhang, Xiaodong Wu, Lingshuang Liu, Xiangman Li, Jianbing Ni
arXiv:2609.40031v1 Announce Type: cross
Abstract: Digital image watermarking is increasingly critical in media contexts, as emerging regulations and industry practices require marking AI-generated co...
By Khaled Abud, Aleksey Yakushev, Aleksandr Akimenkov, Irina Serzhenko, Kirill Aistov, Egor Kovalev, Dmitry Obydenkov, Sergey Lavrushkin, Anastasia Antsiferova, Dmitriy Vatolin, Yury Markin, Kirill Lukianov
arXiv:2610.02010v1 Announce Type: cross
Abstract: Invisible watermarking has become a central tool for tracing AI-generated images, but its robustness against adaptive removal attacks remains an open...
By Kirill Aistov, Khaled Abud, Irina Serzhenko, Egor Kovalev, Aleksey Yakushev, Aleksandr Akimenkov, Dmitry Obydenkov, Yury Markin, Sergey Lavrushkin, Dmitriy Vatolin, Anastasia Antsiferova
Digital image watermarking is increasingly critical in media contexts, as emerging regulations and industry practices require marking AI-generated content and ensuring traceable sources to prevent man...
FeatMark is a watermarking framework that protects images from text‑to‑image diffusion model mimicry attacks by embedding small, scene‑consistent micro‑features instead of pixel‑level perturbations. It constructs domain‑specific feature banks, selects executable features, and injects them via mask‑guided concept editing to create highly localized, natural edits. Experiments on VGGFace2, CelebA‑HQ, and WikiArt show FeatMark remains robust against ten strong watermark removal attacks and several adaptive attacks, with minimal impact on perceptual quality and extending to video mimicry scenarios.
By Haoyang Li, Ruoxi Sun, Qingqing Ye, Benjamin Zi Hao Zhao, Yaxin Xiao, Jason Xue, Haibo Hu
arXiv:2506. 03933v2 Announce Type: replace-cross Abstract: Vision Language Models (VLMs) have shown remarkable capabilities in multimodal understanding, yet their susceptibility to adversarial perturbations poses a significant threat to their reliability in real-world applications.
By Jia Fu, Yongtao Wu, Yihang Chen, Kunyu Peng, Xiao Zhang, Volkan Cevher, Sepideh Pashami, Anders Holst
arXiv:2609.37310v1 Announce Type: cross
Abstract: With LLM watermarking being deployed commercially and now required by regulations, improving its reliability and effectiveness has become crucial. Ye...
By Thibaud Gloaguen, Robin Staab, Martin Vechev
arXiv:2608. 06912v1 Announce Type: new Abstract: The top-$k$ operation is a fundamental building block of modern sparse computation, enabling token routing, expert activation, memory selection, and attention pruning.
By {\L}ukasz Struski, Joanna Wojciechowicz, Jakub Antczak, Marcin Mazur, Kamil Ksi\k{a}\.zek, Jacek Tabor