Adversarial Attack for Robust Watermark Protection Against Inpainting-based and Blind Watermark Removers
Mingzhi Lyu, Yi Huang, Adams Wai-Kin Kong
Abstract
The rise of social media platforms, especially those focusing on image sharing, has made visible watermarks increasingly important in protecting image copyrights. However, multiple studies have revealed that watermarks are vulnerable to both inpainting-based removers and blind watermark removers. Though two adversarial attack methods have been proposed to defend against watermark removers, they are tailored to a particular type of removers in a white-box setting, which significantly limits their practicality and applicability. To date, there is no adversarial attack method that can protect watermarks against the two types of watermark removers simultaneously. In this paper, we propose a novel method, named Adversarial Watermark Defender with Attribution-Guided Perturbation (AWD-AGP), that defends against both inpainting-based and blind watermark removers under a black-box setting. AWD-AGP is the first watermark protection method employing adversarial location. The adversarial location is generated by a Watermark Positioning Network, which predicts an optimal location for watermark placement, making watermark removal challenging for inpainting-based removers. Since inpainting-based removers and blind watermark removers exploit information in different regions of an image to perform removal, we propose an attribution-guided scheme, which automatically assigns attack strengths to different pixels against different removers. With this design, the generated perturbation can attack the two types of watermark removers concurrently. Experiments on seven models, including four inpainting-based removers and three blind watermark removers demonstrate the effectiveness of AWD-AGP.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get df2be234-00ef-4010-a359-878f10d4391fCited by top-tier papers2
- TrustMark: Robust Watermarking and Watermark Removal for Arbitrary Resolution ImagesTu Bui, Shruti Agarwal, John P. CollomosseICCV 2025 · 6 citations
- When and Where Do Data Poisons Attack Textual Inversion?Jeremy Styborski, Mingzhi Lyu, Jiayou Lu, Nupur Kapur et al.ICCV 2025 · 1 citation
Related papers
- Decoder Gradient Shield: Provable and High-Fidelity Prevention of Gradient-Based Box-Free Watermark RemovalHaonan An, Guang Hua, Zhengru Fang, Guowen Xu et al.CVPR 2025
- WRATH: Turning Watermark Robustness Against Itself via a Watermark-Agnostic Black-Box Invalidation AttackNan Jiang, Juan Hu, Bangjie Sun, Terence Sim et al.S&P 2026
- Rethinking the Vulnerability of DNN Watermarking: Are Watermarks Robust against Naturalness-aware Perturbations?Run Wang, Haoxuan Li, Lingzhou Mu, Jixing Ren et al.ACM MM 2022 · 9 citations
- Split then Refine: Stacked Attention-guided ResUNets for Blind Single Image Visible Watermark RemovalXiaodong Cun, Chi-Man PunAAAI 2021 · 66 citations
- A Transfer Attack to Image WatermarksYuepeng Hu, Zhengyuan Jiang, Moyang Guo, Neil Zhenqiang GongICLR 2025
