A Transfer Attack to Image Watermarks
Yuepeng Hu, Zhengyuan Jiang, Moyang Guo, Neil Zhenqiang Gong
摘要
Watermark has been widely deployed by industry to detect AI-generated images. The robustness of such watermark-based detector against evasion attacks in the white-box and black-box settings is well understood in the literature. However, the robustness in the no-box setting is much less understood. In this work, we propose a new transfer evasion attack to image watermark in the no-box setting. Our transfer attack adds a perturbation to a watermarked image to evade multiple surrogate watermarking models trained by the attacker itself, and the perturbed watermarked image also evades the target watermarking model. Our major contribution is to show that, both theoretically and empirically, watermark-based AIgenerated image detector based on existing watermarking methods is not robust to evasion attacks even if the attacker does not have access to the watermarking model nor the detection API. Our code is available at: https://github.com/hifihyp/Watermark-Transfer-Attack .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- UnMarker: A Universal Attack on Defensive Image WatermarkingAndre Kassis, Urs HengartnerS&P 2025
- WRATH: Turning Watermark Robustness Against Itself via a Watermark-Agnostic Black-Box Invalidation AttackNan Jiang, Juan Hu, Bangjie Sun, Terence Sim 等S&P 2026
- Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram MagnitudeZihao Liu, Aobo Chen, Yan Zhang, Wensheng Zhang 等NDSS 2026
- KGMark: A Diffusion Watermark for Knowledge GraphsHongrui Peng, Haolang Lu, Yuanlong Yu, Weiye Fu 等ICML 2025
它引用的顶会 Paper16
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li 等NeurIPS 2022 · 被引用 8,965 次
- Zero-Shot Text-to-Image GenerationAditya Ramesh, Mikhail Pavlov, Gabriel Goh, Scott Gray 等ICML 2021 · 被引用 6,356 次
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz 等ICML 2023 · 被引用 854 次
- Diffusion Models for Adversarial PurificationWeili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao 等ICML 2022 · 被引用 663 次
- The Stable Signature: Rooting Watermarks in Latent Diffusion ModelsPierre Fernandez, Guillaume Couairon, Hervé Jégou, Matthijs Douze 等ICCV 2023 · 被引用 370 次
相关 Paper
- Robustness of AI-Image Detectors: Fundamental Limits and Practical AttacksMehrdad Saberi, Vinu Sankar Sadasivan, Keivan Rezaei, Aounon Kumar 等ICLR 2024 · 被引用 92 次
- Evading Watermark based Detection of AI-Generated ContentZhengyuan Jiang, Jinghuai Zhang, Neil Zhenqiang GongCCS 2023 · 被引用 46 次
- WMCopier: Forging Invisible Watermarks on Arbitrary ImagesZiping Dong, Chao Shuai, Zhongjie Ba, Peng Cheng 等NeurIPS 2025 · 被引用 2 次
- LLM Watermark Evasion via Bias InversionJeongyeon Hwang, Sangdon Park, Jungseul OkICML 2026
- Decoder Gradient Shield: Provable and High-Fidelity Prevention of Gradient-Based Box-Free Watermark RemovalHaonan An, Guang Hua, Zhengru Fang, Guowen Xu 等CVPR 2025
