Black-Box Forgery Attacks on Semantic Watermarks for Diffusion Models
Andreas Müller, Denis Lukovnikov, Jonas Thietke, Asja Fischer, Erwin Quiring
Abstract
Integrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. Specifically, we design two watermark forgery attacks. The first imprints a targeted watermark into real images by manipulating the latent representation of an arbitrary image in an unrelated LDM to get closer to the latent representation of a watermarked image. We also show that this technique can be used for watermark removal. The second attack generates new images with the target watermark by inverting a watermarked image and re-generating it with an arbitrary prompt. Both attacks just need a single reference image with the target watermark. Overall, our findings question the applicability of semantic watermarks by revealing that attackers can easily forge or remove these watermarks under realistic conditions. Github: https://github.com/and-mill/semantic-forgery
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c4831670-05ec-47f4-a33d-1c913cbab33aCited by top-tier papers16
- T2SMark: Balancing Robustness and Diversity in Noise-as-Watermark for Diffusion ModelsJindong Yang, Han Fang, Weiming Zhang, Nenghai Yu et al.NeurIPS 2025 · 13 citations
- Transferable Black-Box One-Shot Forging of Watermarks via Image Preference ModelsTomás Soucek, Sylvestre-Alvise Rebuffi, Pierre Fernandez, Nikola Jovanovic et al.NeurIPS 2025 · 11 citations
- NoisePrints: Distortion-Free Watermarks for Authorship in Private Diffusion ModelsNir Goren, Oren Katzir, Abhinav Nakarmi, Eyal Ronen et al.ICLR 2026 · 5 citations
- The Future Unmarked: Watermark Removal in AI-Generated Images via Next-Frame PredictionHuming Qiu, Zhaoxiang Wang, Mi Zhang, Xiaohan Zhang et al.NeurIPS 2025 · 5 citations
- OptMark: Robust Multi-bit Diffusion Watermarking via Inference Time OptimizationJiazheng Xing, Hai Ci, Hongbin Xu, Hangjie Yuan et al.AAAI 2026 · 2 citations
Builds on28
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Scalable Diffusion Models with TransformersWilliam Peebles, Saining XieICCV 2023 · 5,568 citations
- SDXL: Improving Latent Diffusion Models for High-Resolution Image SynthesisDustin Podell, Zion English, Kyle Lacey, Andreas Blattmann et al.ICLR 2024 · 4,569 citations
Related papers
- SEAL: Semantic Aware Image WatermarkingKasra Arabi, R. Teal Witter, Chinmay Hegde, Niv CohenICCV 2025 · 22 citations
- Rethinking Forgery Attacks on Semantic Watermarks in Black-Box Settings: A Geometric Distortion PerspectiveCHENG-YI LEE, Yichi Zhang, Yuchen Yang, Chun-Shien Lu et al.ICML 2026
- SemBind: Binding Diffusion Watermarks to Semantics Against Black-Box Forgery AttacksXin Zhang, Zijin Yang, Kejiang Chen, Linfeng Ma et al.ICML 2026 · 2 citations
- Attack-Resilient Image Watermarking Using Stable DiffusionLijun Zhang, Xiao Liu, Antoni Viros Martin, Cindy Xiong Bearfield et al.NeurIPS 2024 · 62 citations
- RAVEN: Erasing Invisible Watermarks via Novel View SynthesisFahad Shamshad, Nils Lukas, Karthik NandakumarCVPR 2026 · 3 citations
