WARP: A Unified Benchmark for Invisible Image Watermarking -- Robustness and Protection Against Attacks
Read the original on arXiv AI →The Flow has not summarised this story yet — read it at arXiv AI.
The Flow has not summarised this story yet — read it at arXiv AI.
Digital image watermarking is increasingly critical in media contexts, as emerging regulations and industry practices require marking AI-generated content and ensuring traceable sources to prevent man...
arXiv:2608. 10166v1 Announce Type: cross Abstract: Digital watermarking has emerged as a critical technique for provenance and copyright attribution in AI-generated imagery, yet its robustness against realistic, model-agnostic removal attacks remains poorly explored.
FeatMark is a watermarking framework that protects images from text‑to‑image diffusion model mimicry attacks by embedding small, scene‑consistent micro‑features instead of pixel‑level perturbations. It constructs domain‑specific feature banks, selects executable features, and injects them via mask‑guided concept editing to create highly localized, natural edits. Experiments on VGGFace2, CelebA‑HQ, and WikiArt show FeatMark remains robust against ten strong watermark removal attacks and several adaptive attacks, with minimal impact on perceptual quality and extending to video mimicry scenarios.
Text-to-image diffusion models enable data-efficient "mimicry" attacks, wherein adversaries fine-tune the model on a handful of public photos to synthesize convincing forgeries of a target individual....
arXiv:2609.39623v1 Announce Type: new Abstract: The proliferation of high-fidelity generative editing models has made it possible to inject violent or sexual content into otherwise ordinary images wh...
The paper introduces the first systematic robustness benchmark for local invisible image watermarking, evaluating five methods across 55 image transformations that include signal distortions, coordinate misalignments, indirect local edits, and direct watermark edits. Results show that all methods are vulnerable to some transformation, with MaskWM achieving the best payload recovery and localization but at the cost of image quality. The study highlights that robustness varies strongly with transformation type, especially noting that geometric misalignment and generative local edits can completely disrupt payload recovery.