Pith. sign in

REVIEW 3 cited by

A Transfer Attack to Image Watermarks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2403.15365 v4 pith:FMYJW3EO submitted 2024-03-22 cs.CR cs.CLcs.LG

classification cs.CRcs.CLcs.LG
keywords imagewatermarkingattackevasiontransferai-generatedattackerattacks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Watermark has been widely deployed by industry to detect AI-generated images. The robustness of such watermark-based detector against evasion attacks in the white-box and black-box settings is well understood in the literature. However, the robustness in the no-box setting is much less understood. In this work, we propose a new transfer evasion attack to image watermark in the no-box setting. Our transfer attack adds a perturbation to a watermarked image to evade multiple surrogate watermarking models trained by the attacker itself, and the perturbed watermarked image also evades the target watermarking model. Our major contribution is to show that, both theoretically and empirically, watermark-based AI-generated image detector based on existing watermarking methods is not robust to evasion attacks even if the attacker does not have access to the watermarking model nor the detection API. Our code is available at: https://github.com/hifi-hyp/Watermark-Transfer-Attack.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. KGMark: A Diffusion Watermark for Knowledge Graphs

    cs.CR 2025-05 reject novelty 5.0 of 10

    KGMark embeds a detectable watermark into knowledge graph embeddings via diffusion inversion, with graph alignment and a learned mask, and reports high AUC under editing attacks.

  2. When There Is No Decoder: Removing Watermarks from Stable Diffusion Models in a No-box Setting

    cs.CR 2025-07 reject novelty 4.0 of 10

    Blur-plus-deblur and generator fine-tuning can push watermark bit accuracy toward chance, but only when the attacker can train a surrogate decoder that matches the target's architecture.

  3. Challenges in GenAI and Authentication: a scoping review

    cs.CR 2025-07 reject novelty 2.0 of 10

    A scoping review of 13 selected papers summarizes security challenges, attacks, solutions, and research gaps in authentication under generative AI.

Pith tools