Residual Transferability in Neural Image Watermarking
Summary
This paper formalizes residual transferability in neural image watermarking, showing architectural design is crucial for reducing transferability, and proposes CoverLock as a plug-and-play defense to enhance security.
View Cached Full Text
Cached at: 09/29/26, 08:12 AM
Paper page - Residual Transferability in Neural Image Watermarking
Source: https://huggingface.co/papers/2609.32241
Abstract
Neuralimagewatermarkscanbeforgedbyextractingwatermark-bearingresidualsfromreleasedimagesandtransferringthemtounrelatedcontent.Whilepriorworkhasdemonstratedthisvulnerability,whatmakestheseresidualstransferableremainspoorlyunderstood.Weformalizethisvulnerabilitywithresidualtransferability(RT),ametricthatquantifieshowwellwatermarkevidenceremainsdecodableaftertransferacrossunrelatedimages.Throughcomparativeanalysesandcontrolledinterventions,wefindthatcommontraining-sidevariationsdonotaccountforthelargeRTdifferencesacrosswatermarkingsystems;instead,architecturaldesignplaysacentralrole.Bycontrastinghigh-andlow-RTsystemsandvalidatingtheirarchitecturaldifferencesthroughcontrolledinterventions,weidentifytwomechanismsthatstrengthenthedependenceofwatermarkevidenceonthecoverimage,therebysuppressingtheresidualtransferability.Thesefindingsprovideconcretedesignguidancefordevelopingmoreforgery-resistantwatermarkingarchitectures.Complementarily,forexistingwatermarkingsystemswherearchitecturalredesignisimpractical,weintroduceCoverLock,aplug-and-playstrategyforexistingwatermarkingsystemsthatstrengthenssuchimagedependencewithoutarchitecturalredesign.Acrossrepresentativewatermarkingsystemsexhibitinghighresidualtransferability,CoverLockachievesamorefavorablesecurity--robustnesstrade-offthanbothtraditionalhandcrafteddefensesandlearnedclassifier-baseddefenses.
View arXiv pageView PDFAdd to collection
Get this paper in your agent:
hf papers read 2609\.32241
Don’t have the latest CLI?curl \-LsSf https://hf\.co/cli/install\.sh \| bash
Models citing this paper0
No model linking this paper
Cite arxiv.org/abs/2609.32241 in a model README.md to link it from this page.
Datasets citing this paper0
No dataset linking this paper
Cite arxiv.org/abs/2609.32241 in a dataset README.md to link it from this page.
Spaces citing this paper0
No Space linking this paper
Cite arxiv.org/abs/2609.32241 in a Space README.md to link it from this page.
Collections including this paper0
No Collection including this paper
Add this paper to acollectionto link it from this page.
Similar Articles
Why most "AI watermarks" die the moment someone screenshots the image (and the layered fix that actually survives it)
Explains why metadata-based AI watermarks like C2PA fail when images are screenshotted or re-encoded, and proposes a layered approach combining frequency-domain, neural, and perceptual fingerprinting watermarking that survives real-world social media round-trips.
Watermarking for Proprietary Dataset Protection
This paper proposes using watermarking techniques to protect proprietary datasets from unauthorized use in training generative models, and demonstrates that watermark-based dataset inference can achieve comparable membership detection performance to traditional loss-based methods under certain conditions.
A Locally Tokenized Generative Model for Robust Time-Series Watermarking
This paper introduces a locally tokenized generative model for robust watermarking in multivariate time-series data, addressing reliability issues under post-editing attacks by using bounded temporal neighborhoods for token recovery.
Linguistic Holonomy and Statistical Watermarks: Inner Geometry of Meaning-Preserving Transformations
The paper analyzes statistical watermarks in language models by formalizing meaning-preserving transformations using linguistic holonomy, proving that watermark detection depends on the survival of seeding windows and establishing a decay law for the watermark signal.
Making Open-Source Text LLM Watermarks Durable Against Merging
This paper proposes Merge-Adversarial Training to make text watermarks in open-source LLMs survive model merging, outperforming baselines while preserving downstream capabilities.