Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

Invisible Image Watermarks Are Provably Removable Using Generative AI

About

Invisible watermarks safeguard images' copyrights by embedding hidden messages only detectable by owners. They also prevent people from misusing images, especially those generated by AI models. We propose a family of regeneration attacks to remove these invisible watermarks. The proposed attack method first adds random noise to an image to destroy the watermark and then reconstructs the image. This approach is flexible and can be instantiated with many existing image-denoising algorithms and pre-trained generative models such as diffusion models. Through formal proofs and extensive empirical evaluations, we demonstrate that pixel-level invisible watermarks are vulnerable to this regeneration attack. Our results reveal that, across four different pixel-level watermarking schemes, the proposed method consistently achieves superior performance compared to existing attack techniques, with lower detection rates and higher image quality. However, watermarks that keep the image semantically similar can be an alternative defense against our attacks. Our finding underscores the need for a shift in research/industry emphasis from invisible watermarks to semantic-preserving watermarks. Code is available at https://github.com/XuandongZhao/WatermarkAttacker

Xuandong Zhao, Kexun Zhang, Zihao Su, Saastha Vasan, Ilya Grishchenko, Christopher Kruegel, Giovanni Vigna, Yu-Xiang Wang, Lei Li• 2023

Related benchmarks

TaskDatasetResultRank
Post-attack image integrityOpenImage
PSNR30.52
24
Post-attack image integrityCOCO
PSNR30.15
24
Watermark VerificationDiffusionDB (test)
TPR@1%FPR45.4
15
Quality PreservationSD-Prompts (test)
FID49.78
13
Quality PreservationDiffusionDB (test)
FID47.83
13
Quality PreservationMS-COCO (test)
FID42.36
13
Watermark Removal AttackSS in-processing watermarking scheme
Bit Accuracy61.4
13
Watermark Removal AttackHiDDeN Watermarking Scheme
PSNR30.22
9
Watermark Removal AttackYu Watermarking Scheme
PSNR31.96
9
Watermark Removal AttackSS Watermarking Scheme
PSNR27.01
9
Showing 10 of 19 rows

Other info

Code

Follow for update