Megadose AI progress, ranked and analyzed.

Residual Transferability in Neural Image Watermarking

· HF Daily Papers ·
The paper says forged neural image watermarks can survive transfer because some systems fail to bind the watermark evidence tightly to the original image.

The authors define “residual transferability” as a way to measure how well watermark evidence remains decodable after being moved onto unrelated content. Their comparisons point less to training choices and more to architecture as the driver of large differences between systems. They identify two architectural mechanisms that make watermark evidence more cover-dependent and harder to transplant. For systems that cannot be redesigned, they propose CoverLock as a plug-in defense with a better security-robustness trade-off in their tests. HF Daily Papers' note

score 4

Categories: Research