🤖 AI Summary
This study addresses the limitations of existing invisible image watermarking benchmarks in comprehensively evaluating the robustness and attack resistance of state-of-the-art methods by constructing the largest unified evaluation framework in the field. This framework pioneers the integration of 32 watermarking techniques—spanning traditional, deep learning-based, and generative approaches—with 34 removal methods, while introducing advanced attack strategies including adversarial attacks, purification, and re-embedding to provide standardized, reproducible protocols for assessing perceptual quality and robustness. The research reveals intrinsic correlations between specific watermarking algorithms and particular attacks, as well as critical re-embedding vulnerabilities. Furthermore, it identifies the most robust solutions and systematically quantifies the differential vulnerabilities of various methods under complex attack conditions.
📝 Abstract
Digital image watermarking is increasingly critical in media contexts, as emerging regulations and industry practices require marking AI-generated content and ensuring traceable sources to prevent manipulation or misuse. Recent advances in invisible watermarking methods highlight the need to update existing benchmarking practices to reflect current techniques and evaluation criteria.
We address this by introducing WARP -- a unified framework and benchmark for evaluating the robustness of invisible watermarks. WARP incorporates 32 recent classical, deep, and generative watermarking methods, as well as 34 different erasing techniques, ranging from traditional distortions to more sophisticated adversarial, purification, and re-embedding attacks. It provides standardized, reproducible, and easily scalable protocols for evaluating perceptual quality, watermark readability, and attack resilience.
Using WARP, we extensively evaluate current invisible watermarking techniques, collecting the largest robustness benchmark in the field. Results identify the most robust approaches under both distortion and adversarial conditions, and reveal consistent relationships between watermarking methods and the attack strategies most effective against them. Our experiments also highlight that some of the watermarking methods considered are highly vulnerable to reembedding, even if they are robust to standard distortions. The code is made available at https://github.com/ispras/wibe.