WMCopier: Forging Invisible Image Watermarks on Arbitrary Images

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Dong, Ziping, Shuai, Chao, Ba, Zhongjie, Cheng, Peng, Qin, Zhan, Wang, Qinglong, Ren, Kui
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915572791377920
author Dong, Ziping
Shuai, Chao
Ba, Zhongjie
Cheng, Peng
Qin, Zhan
Wang, Qinglong
Ren, Kui
author_facet Dong, Ziping
Shuai, Chao
Ba, Zhongjie
Cheng, Peng
Qin, Zhan
Wang, Qinglong
Ren, Kui
contents Invisible Image Watermarking is crucial for ensuring content provenance and accountability in generative AI. While Gen-AI providers are increasingly integrating invisible watermarking systems, the robustness of these schemes against forgery attacks remains poorly characterized. This is critical, as forging traceable watermarks onto illicit content leads to false attribution, potentially harming the reputation and legal standing of Gen-AI service providers who are not responsible for the content. In this work, we propose WMCopier, an effective watermark forgery attack that operates without requiring any prior knowledge of or access to the target watermarking algorithm. Our approach first models the target watermark distribution using an unconditional diffusion model, and then seamlessly embeds the target watermark into a non-watermarked image via a shallow inversion process. We also incorporate an iterative optimization procedure that refines the reconstructed image to further trade off the fidelity and forgery efficiency. Experimental results demonstrate that WMCopier effectively deceives both open-source and closed-source watermark systems (e.g., Amazon's system), achieving a significantly higher success rate than existing methods. Additionally, we evaluate the robustness of forged samples and discuss the potential defenses against our attack.
format Preprint
id arxiv_https___arxiv_org_abs_2503_22330
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle WMCopier: Forging Invisible Image Watermarks on Arbitrary Images
Dong, Ziping
Shuai, Chao
Ba, Zhongjie
Cheng, Peng
Qin, Zhan
Wang, Qinglong
Ren, Kui
Cryptography and Security
Computer Vision and Pattern Recognition
Invisible Image Watermarking is crucial for ensuring content provenance and accountability in generative AI. While Gen-AI providers are increasingly integrating invisible watermarking systems, the robustness of these schemes against forgery attacks remains poorly characterized. This is critical, as forging traceable watermarks onto illicit content leads to false attribution, potentially harming the reputation and legal standing of Gen-AI service providers who are not responsible for the content. In this work, we propose WMCopier, an effective watermark forgery attack that operates without requiring any prior knowledge of or access to the target watermarking algorithm. Our approach first models the target watermark distribution using an unconditional diffusion model, and then seamlessly embeds the target watermark into a non-watermarked image via a shallow inversion process. We also incorporate an iterative optimization procedure that refines the reconstructed image to further trade off the fidelity and forgery efficiency. Experimental results demonstrate that WMCopier effectively deceives both open-source and closed-source watermark systems (e.g., Amazon's system), achieving a significantly higher success rate than existing methods. Additionally, we evaluate the robustness of forged samples and discuss the potential defenses against our attack.
title WMCopier: Forging Invisible Image Watermarks on Arbitrary Images
topic Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2503.22330