Robustness of Image Watermarking

Benchmarking and attacking invisible watermarks for AI-generated images.

Invisible watermarks are a key tool for marking AI-generated content, but they are only useful if they survive removal attempts. We developed WIBE, a framework for benchmarking and evaluating watermarks for generated images (Yakushev et al., 2025) (code), and a watermark overwriting attack that completely removes StegaStamp watermarks with minimal quality loss, developed for the NeurIPS “Erasing the Invisible” competition (Serzhenko et al., 2025).

Building on WIBE, we released WARP, a unified benchmark that evaluates 32 invisible watermarking methods against 34 erasing techniques, from simple distortions to adversarial, purification and re-embedding attacks (Abud et al., 2026).

References

2026

  1. ACM MM
    WARP: A Unified Benchmark for Invisible Image Watermarking – Robustness and Protection Against Attacks
    Khaled Abud, Aleksey Yakushev, Aleksandr Akimenkov, Irina Serzhenko, Kirill Aistov, Egor Kovalev, Dmitry Obydenkov, Sergey Lavrushkin, Anastasia Antsiferova, Dmitriy Vatolin, Yury Markin, and Kirill Lukianov
    In Proceedings of the 34th ACM International Conference on Multimedia, 2026

2025

  1. ASE
    WIBE: Watermarks for generated Images–Benchmarking & Evaluation
    Aleksey Yakushev, Aleksandr Akimenkov, Khaled Abud, Dmitry Obydenkov, Irina Serzhenko, Kirill Aistov, Egor Kovalev, Stanislav Fomin, Anastasia Antsiferova, Kirill Lukianov, and Yury Markin
    In 2025 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2025
  2. arXiv
    Watermark Overwriting Attack on StegaStamp algorithm
    IF Serzhenko, LA Khaertdinova, MA Pautov, and AV Antsiferova
    2025