Invisible Image Watermarks Are Provably Removable Using Generative AI

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhao, Xuandong, Zhang, Kexun, Su, Zihao, Vasan, Saastha, Grishchenko, Ilya, Kruegel, Christopher, Vigna, Giovanni, Wang, Yu-Xiang, Li, Lei
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917824113410048
author Zhao, Xuandong
Zhang, Kexun
Su, Zihao
Vasan, Saastha
Grishchenko, Ilya
Kruegel, Christopher
Vigna, Giovanni
Wang, Yu-Xiang
Li, Lei
author_facet Zhao, Xuandong
Zhang, Kexun
Su, Zihao
Vasan, Saastha
Grishchenko, Ilya
Kruegel, Christopher
Vigna, Giovanni
Wang, Yu-Xiang
Li, Lei
contents Invisible watermarks safeguard images' copyrights by embedding hidden messages only detectable by owners. They also prevent people from misusing images, especially those generated by AI models. We propose a family of regeneration attacks to remove these invisible watermarks. The proposed attack method first adds random noise to an image to destroy the watermark and then reconstructs the image. This approach is flexible and can be instantiated with many existing image-denoising algorithms and pre-trained generative models such as diffusion models. Through formal proofs and extensive empirical evaluations, we demonstrate that pixel-level invisible watermarks are vulnerable to this regeneration attack. Our results reveal that, across four different pixel-level watermarking schemes, the proposed method consistently achieves superior performance compared to existing attack techniques, with lower detection rates and higher image quality. However, watermarks that keep the image semantically similar can be an alternative defense against our attacks. Our finding underscores the need for a shift in research/industry emphasis from invisible watermarks to semantic-preserving watermarks. Code is available at https://github.com/XuandongZhao/WatermarkAttacker
format Preprint
id arxiv_https___arxiv_org_abs_2306_01953
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Invisible Image Watermarks Are Provably Removable Using Generative AI
Zhao, Xuandong
Zhang, Kexun
Su, Zihao
Vasan, Saastha
Grishchenko, Ilya
Kruegel, Christopher
Vigna, Giovanni
Wang, Yu-Xiang
Li, Lei
Cryptography and Security
Artificial Intelligence
Computer Vision and Pattern Recognition
Invisible watermarks safeguard images' copyrights by embedding hidden messages only detectable by owners. They also prevent people from misusing images, especially those generated by AI models. We propose a family of regeneration attacks to remove these invisible watermarks. The proposed attack method first adds random noise to an image to destroy the watermark and then reconstructs the image. This approach is flexible and can be instantiated with many existing image-denoising algorithms and pre-trained generative models such as diffusion models. Through formal proofs and extensive empirical evaluations, we demonstrate that pixel-level invisible watermarks are vulnerable to this regeneration attack. Our results reveal that, across four different pixel-level watermarking schemes, the proposed method consistently achieves superior performance compared to existing attack techniques, with lower detection rates and higher image quality. However, watermarks that keep the image semantically similar can be an alternative defense against our attacks. Our finding underscores the need for a shift in research/industry emphasis from invisible watermarks to semantic-preserving watermarks. Code is available at https://github.com/XuandongZhao/WatermarkAttacker
title Invisible Image Watermarks Are Provably Removable Using Generative AI
topic Cryptography and Security
Artificial Intelligence
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2306.01953