Box-Free Model Watermarks are Prone to Black-Box Removal Attacks
Summary
Researchers found that box-free model watermarking (a technique to protect ownership of AI models by embedding hidden marks), which is used for image processing tasks, can be defeated through black-box removal attacks (attacks where the attacker cannot see inside the protected model). The study describes three methods attackers could use to strip watermarks from protected models while keeping the images looking good, showing that current watermarking approaches are vulnerable.
Classification
Related Issues
Original source: http://ieeexplore.ieee.org/document/11495080
First tracked: August 6, 2026 at 08:04 PM
Classified by LLM (prompt v3) · confidence: 85%