Benchmarking and attacking invisible watermarks for AI-generated images.
Invisible watermarks are a key tool for marking AI-generated content, but they are only useful if they survive removal attempts. We developed WIBE, a framework for benchmarking and evaluating watermarks for generated images (Yakushev et al., 2025) (code), and a watermark overwriting attack that completely removes StegaStamp watermarks with minimal quality loss, developed for the NeurIPS “Erasing the Invisible” competition (Serzhenko et al., 2025).
Building on WIBE, we released WARP, a unified benchmark that evaluates 32 invisible watermarking methods against 34 erasing techniques, from simple distortions to adversarial, purification and re-embedding attacks (Abud et al., 2026).
References
2026
ACM MM
WARP: A Unified Benchmark for Invisible Image Watermarking – Robustness and Protection Against Attacks
A unified benchmark for invisible image watermarking that evaluates 32 watermarking methods against 34 erasing techniques, from simple distortions to adversarial, purification and re-embedding attacks.
@inproceedings{abudWarp2026,title={{WARP: A Unified Benchmark for Invisible Image Watermarking -- Robustness and Protection Against Attacks}},author={Abud, Khaled and Yakushev, Aleksey and Akimenkov, Aleksandr and Serzhenko, Irina and Aistov, Kirill and Kovalev, Egor and Obydenkov, Dmitry and Lavrushkin, Sergey and Antsiferova, Anastasia and Vatolin, Dmitriy and Markin, Yury and Lukianov, Kirill},year={2026},booktitle={Proceedings of the 34th ACM International Conference on Multimedia},}
2025
ASE
WIBE: Watermarks for generated Images–Benchmarking & Evaluation
Aleksey Yakushev, Aleksandr Akimenkov, Khaled Abud, Dmitry Obydenkov, Irina Serzhenko, Kirill Aistov, Egor Kovalev, Stanislav Fomin, Anastasia Antsiferova, Kirill Lukianov, and Yury Markin
In 2025 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2025
As invisible image watermarking gains importance for verifying AI-generated content, consistency and reproducibility remain major challenges due to the diverse methods, datasets, attacks, and metrics.We aim to provide a flexible, extensible, and user-friendly framework that enables systematic testing of watermarking methods under various conditions.We developed WIBE, a framework with command-line interfaces and YAML configuration support, enabling users to evaluate a wide range of image watermarking algorithms on various datasets, apply configurable attack scenarios, and compute standard performance metrics. WIBE includes a library of pre-implemented methods and supports integration of new watermarking techniques, attacks, metrics, and datasets through a plugin-based architecture.WIBE enables rapid prototyping, reproducible experiments, and insightful comparison of watermarking robustness …
@inproceedings{markinWibe2025,title={{WIBE: Watermarks for generated Images–Benchmarking & Evaluation}},author={Yakushev, Aleksey and Akimenkov, Aleksandr and Abud, Khaled and Obydenkov, Dmitry and Serzhenko, Irina and Aistov, Kirill and Kovalev, Egor and Fomin, Stanislav and Antsiferova, Anastasia and Lukianov, Kirill and Markin, Yury},year={2025},booktitle={2025 40th IEEE/ACM International Conference on Automated Software Engineering (ASE)},}
arXiv
Watermark Overwriting Attack on StegaStamp algorithm
IF Serzhenko, LA Khaertdinova, MA Pautov, and AV Antsiferova
This paper presents an attack method on the StegaStamp watermarking algorithm that completely removes watermarks from an image with minimal quality loss, developed as part of the NeurIPS "Erasing the invisible" competition.
@misc{antsiferovaWatermark2025,title={{Watermark Overwriting Attack on StegaStamp algorithm}},author={Serzhenko, IF and Khaertdinova, LA and Pautov, MA and Antsiferova, AV},year={2025},journal={arXiv preprint arXiv:2505.01474},}