SHIFT: Stochastic Hidden-Trajectory Deflection for Removing Diffusion-based Watermark

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bao, Rui, Gao, Zheng, Li, Xiaoyu, Feng, Xiaoyan, Song, Yang, Jiang, Jiaojiao
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914436614193152
author Bao, Rui
Gao, Zheng
Li, Xiaoyu
Feng, Xiaoyan
Song, Yang
Jiang, Jiaojiao
author_facet Bao, Rui
Gao, Zheng
Li, Xiaoyu
Feng, Xiaoyan
Song, Yang
Jiang, Jiaojiao
contents Diffusion-based watermarking methods embed verifiable marks by manipulating the initial noise or the reverse diffusion trajectory. However, these methods share a critical assumption: verification can succeed only if the diffusion trajectory can be faithfully reconstructed. This reliance on trajectory recovery constitutes a fundamental and exploitable vulnerability. We propose $\underline{\mathbf{S}}$tochastic $\underline{\mathbf{Hi}}$dden-Trajectory De$\underline{\mathbf{f}}$lec$\underline{\mathbf{t}}$ion ($\mathbf{SHIFT}$), a training-free attack that exploits this common weakness across diverse watermarking paradigms. SHIFT leverages stochastic diffusion resampling to deflect the generative trajectory in latent space, making the reconstructed image statistically decoupled from the original watermark-embedded trajectory while preserving strong visual quality and semantic consistency. Extensive experiments on nine representative watermarking methods spanning noise-space, frequency-domain, and optimization-based paradigms show that SHIFT achieves 95%--100% attack success rates with nearly no loss in semantic quality, without requiring any watermark-specific knowledge or model retraining.
format Preprint
id arxiv_https___arxiv_org_abs_2603_29742
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle SHIFT: Stochastic Hidden-Trajectory Deflection for Removing Diffusion-based Watermark
Bao, Rui
Gao, Zheng
Li, Xiaoyu
Feng, Xiaoyan
Song, Yang
Jiang, Jiaojiao
Computer Vision and Pattern Recognition
Cryptography and Security
Diffusion-based watermarking methods embed verifiable marks by manipulating the initial noise or the reverse diffusion trajectory. However, these methods share a critical assumption: verification can succeed only if the diffusion trajectory can be faithfully reconstructed. This reliance on trajectory recovery constitutes a fundamental and exploitable vulnerability. We propose $\underline{\mathbf{S}}$tochastic $\underline{\mathbf{Hi}}$dden-Trajectory De$\underline{\mathbf{f}}$lec$\underline{\mathbf{t}}$ion ($\mathbf{SHIFT}$), a training-free attack that exploits this common weakness across diverse watermarking paradigms. SHIFT leverages stochastic diffusion resampling to deflect the generative trajectory in latent space, making the reconstructed image statistically decoupled from the original watermark-embedded trajectory while preserving strong visual quality and semantic consistency. Extensive experiments on nine representative watermarking methods spanning noise-space, frequency-domain, and optimization-based paradigms show that SHIFT achieves 95%--100% attack success rates with nearly no loss in semantic quality, without requiring any watermark-specific knowledge or model retraining.
title SHIFT: Stochastic Hidden-Trajectory Deflection for Removing Diffusion-based Watermark
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2603.29742