Residual Transferability in Neural Image Watermarking

Hugging Face Daily Papers Papers

Summary

This paper formalizes residual transferability in neural image watermarking, showing architectural design is crucial for reducing transferability, and proposes CoverLock as a plug-and-play defense to enhance security.

Neural image watermarks can be forged by extracting watermark-bearing residuals from released images and transferring them to unrelated content. While prior work has demonstrated this vulnerability, what makes these residuals transferable remains poorly understood. We formalize this vulnerability with residual transferability (RT), a metric that quantifies how well watermark evidence remains decodable after transfer across unrelated images. Through comparative analyses and controlled interventions, we find that common training-side variations do not account for the large RT differences across watermarking systems; instead, architectural design plays a central role. By contrasting high- and low-RT systems and validating their architectural differences through controlled interventions, we identify two mechanisms that strengthen the dependence of watermark evidence on the cover image, thereby suppressing the residual transferability. These findings provide concrete design guidance for developing more forgery-resistant watermarking architectures. Complementarily, for existing watermarking systems where architectural redesign is impractical, we introduce CoverLock, a plug-and-play strategy for existing watermarking systems that strengthens such image dependence without architectural redesign. Across representative watermarking systems exhibiting high residual transferability, CoverLock achieves a more favorable security--robustness trade-off than both traditional handcrafted defenses and learned classifier-based defenses.
Original Article
View Cached Full Text

Cached at: 09/29/26, 08:12 AM

Paper page - Residual Transferability in Neural Image Watermarking

Source: https://huggingface.co/papers/2609.32241

Abstract

Neuralimagewatermarkscanbeforgedbyextractingwatermark-bearingresidualsfromreleasedimagesandtransferringthemtounrelatedcontent.Whilepriorworkhasdemonstratedthisvulnerability,whatmakestheseresidualstransferableremainspoorlyunderstood.Weformalizethisvulnerabilitywithresidualtransferability(RT),ametricthatquantifieshowwellwatermarkevidenceremainsdecodableaftertransferacrossunrelatedimages.Throughcomparativeanalysesandcontrolledinterventions,wefindthatcommontraining-sidevariationsdonotaccountforthelargeRTdifferencesacrosswatermarkingsystems;instead,architecturaldesignplaysacentralrole.Bycontrastinghigh-andlow-RTsystemsandvalidatingtheirarchitecturaldifferencesthroughcontrolledinterventions,weidentifytwomechanismsthatstrengthenthedependenceofwatermarkevidenceonthecoverimage,therebysuppressingtheresidualtransferability.Thesefindingsprovideconcretedesignguidancefordevelopingmoreforgery-resistantwatermarkingarchitectures.Complementarily,forexistingwatermarkingsystemswherearchitecturalredesignisimpractical,weintroduceCoverLock,aplug-and-playstrategyforexistingwatermarkingsystemsthatstrengthenssuchimagedependencewithoutarchitecturalredesign.Acrossrepresentativewatermarkingsystemsexhibitinghighresidualtransferability,CoverLockachievesamorefavorablesecurity--robustnesstrade-offthanbothtraditionalhandcrafteddefensesandlearnedclassifier-baseddefenses.

View arXiv pageView PDFAdd to collection

Get this paper in your agent:

hf papers read 2609\.32241

Don’t have the latest CLI?curl \-LsSf https://hf\.co/cli/install\.sh \| bash

Models citing this paper0

No model linking this paper

Cite arxiv.org/abs/2609.32241 in a model README.md to link it from this page.

Datasets citing this paper0

No dataset linking this paper

Cite arxiv.org/abs/2609.32241 in a dataset README.md to link it from this page.

Spaces citing this paper0

No Space linking this paper

Cite arxiv.org/abs/2609.32241 in a Space README.md to link it from this page.

Collections including this paper0

No Collection including this paper

Add this paper to acollectionto link it from this page.

Similar Articles

Watermarking for Proprietary Dataset Protection

arXiv cs.LG

This paper proposes using watermarking techniques to protect proprietary datasets from unauthorized use in training generative models, and demonstrates that watermark-based dataset inference can achieve comparable membership detection performance to traditional loss-based methods under certain conditions.