DWBench: Holistic Evaluation of Watermark for Dataset Copyright Auditing
Xiao Ren, Xinyi Yu, Linkang Du, Min Chen, Yuanchao Shu, Zhou Su, Yunjun Gao, Zhikun Zhang
Abstract
The surging demand for large-scale datasets in deep learning has heightened the need for effective copyright protection, given the risks of unauthorized use to data owners. Although the dataset watermark technique holds promise for auditing and verifying usage, existing methods are hindered by inconsistent evaluations, which impede fair comparisons and assessments of real-world viability. To address this gap, we organize existing methods according to two key dimensions, implementation and verification, to support a consistent analysis and evaluation pipeline across tasks. Based on this framework, we develop DWBench, a unified benchmark and open-source toolkit for systematically evaluating image dataset watermark techniques in classification and generation tasks. Using DWBench, we assess 25 representative methods under standardized conditions, perturbation-based robustness tests, multi-watermark coexistence, and multi-user interference. To enable accurate and reproducible benchmarking, we use TPR@5%FPR for unified sample-level comparison and introduce the verification success rate (VSR) for dataset-level auditing. Key findings reveal that standard single-watermark evaluations tend to overestimate practical auditability. Methods that verify reliably in isolation often suffer from performance degradation at low watermarked-sample ratios, while yielding ambiguous ownership evidence in complex multi-user and multi-watermark settings. We hope that DWBench can facilitate advances in watermark reliability and practicality, thus strengthening copyright safeguards in the face of widespread AI-driven data exploitation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7fdfaa1e-dab3-4a51-a1d5-db9d268a4e10Builds on16
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Artificial Fingerprinting for Generative Models: Rooting Deepfake Attribution in Training DataNing Yu, Vladislav Skripniuk, Sahar Abdelnabi, Mario FritzICCV 2021 · 305 citations
- Witches' Brew: Industrial Scale Data Poisoning via Gradient MatchingJonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja et al.ICLR 2021 · 268 citations
- Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from ScratchHossein Souri, Liam Fowl, Rama Chellappa, Micah Goldblum et al.NeurIPS 2022 · 184 citations
- Untargeted Backdoor Watermark: Towards Harmless and Stealthy Dataset Copyright ProtectionYiming Li, Yang Bai, Yong Jiang, Yong Yang et al.NeurIPS 2022 · 161 citations
Related papers
- Analyzing and Evaluating Unbiased Language Model WatermarkYihan Wu, Xuehao Cui, Ruibo Chen, Heng HuangICLR 2026 · 7 citations
- WaterBench: Towards Holistic Evaluation of Watermarks for Large Language ModelsShangqing Tu, Yuliang Sun, Yushi Bai, Jifan Yu et al.ACL 2024
- SoK: Dataset Copyright Auditing in Machine Learning SystemsLinkang Du, Xuanru Zhou, Min Chen, Chusong Zhang et al.S&P 2025
- Copy, Right? A Testing Framework for Copyright Protection of Deep Learning ModelsJialuo Chen, Jingyi Wang, Tinglan Peng, Youcheng Sun et al.S&P 2022 · 94 citations
- Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to AdvancesShilin Lu, Zihan Zhou, Jiayou Lu, Yuanzhi Zhu et al.ICLR 2025
