Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
119 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Stable Signature is Unstable: Removing Image Watermark from Diffusion Models (2405.07145v1)

Published 12 May 2024 in cs.CR and cs.CV

Abstract: Watermark has been widely deployed by industry to detect AI-generated images. A recent watermarking framework called \emph{Stable Signature} (proposed by Meta) roots watermark into the parameters of a diffusion model's decoder such that its generated images are inherently watermarked. Stable Signature makes it possible to watermark images generated by \emph{open-source} diffusion models and was claimed to be robust against removal attacks. In this work, we propose a new attack to remove the watermark from a diffusion model by fine-tuning it. Our results show that our attack can effectively remove the watermark from a diffusion model such that its generated images are non-watermarked, while maintaining the visual quality of the generated images. Our results highlight that Stable Signature is not as stable as previously thought.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (4)
  1. Yuepeng Hu (14 papers)
  2. Zhengyuan Jiang (12 papers)
  3. Moyang Guo (7 papers)
  4. Neil Gong (14 papers)
Citations (4)

Summary

We haven't generated a summary for this paper yet.