UnMarker: A Universal Attack on Defensive Image Watermarking
Andre Kassis, Urs Hengartner

TL;DR
UnMarker is a novel universal attack that effectively disrupts various defensive image watermarking schemes, including semantic watermarks, without requiring detector feedback or advanced knowledge, thus challenging their viability for deepfake detection.
Contribution
We introduce UnMarker, the first practical universal attack on defensive watermarking that works without detector feedback or detailed scheme knowledge, significantly weakening watermark-based defenses.
Findings
UnMarker defeats state-of-the-art watermarking schemes.
It reduces semantic watermark detection to 43%.
It maintains high image quality while erasing watermarks.
Abstract
Reports regarding the misuse of Generative AI (GenAI) to create deepfakes are frequent. Defensive watermarking enables GenAI providers to hide fingerprints in their images and use them later for deepfake detection. Yet, its potential has not been fully explored. We present UnMarker -- the first practical universal attack on defensive watermarking. Unlike existing attacks, UnMarker requires no detector feedback, no unrealistic knowledge of the watermarking scheme or similar models, and no advanced denoising pipelines that may not be available. Instead, being the product of an in-depth analysis of the watermarking paradigm revealing that robust schemes must construct their watermarks in the spectral amplitudes, UnMarker employs two novel adversarial optimizations to disrupt the spectra of watermarked images, erasing the watermarks. Evaluations against SOTA schemes prove UnMarker's…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Steganography and Watermarking Techniques · Internet Traffic Analysis and Secure E-voting · Digital Rights Management and Security
