NORMA eResearch @NCI Library

FLEXMark: Evaluating Watermark Robustness and Attribution Reliability Under Redistribution and Adaptive AI Laundering

Nicholas, Natalia Ellen, Rustam, Furqan and Jurcut, Anca Delia (2026) FLEXMark: Evaluating Watermark Robustness and Attribution Reliability Under Redistribution and Adaptive AI Laundering. In: Proceedings - 47th IEEE Symposium on Security and Privacy Workshops, SPW 2026. IEEE, San Francisco, CA, pp. 238-249. ISBN 979-831951070-9

Full text not available from this repository.
Official URL: https://doi.org/10.1109/SPW72489.2026.00028

Abstract

Digital watermarking is increasingly proposed as a durable complement to cryptographic provenance metadata in content authenticity workflows in the age of generative AI. However, most watermarking systems are evaluated primarily using signal-level robustness metrics, without aligning performance to verification-oriented security objectives or enforcing comparable imperceptibility constraints across methods. Consequently, it remains unclear which embedding strategies provide reliable attribution under realistic redistribution and adaptive removal in controlled image-based evaluation settings. We introduce FLEXMark, a protocol-level evaluation framework for security and verification-aligned watermark assessment. FLEXMark enforces a shared residual distortion budget, structured provenance-realistic payloads, a standardized redistribution attack suite, and decision-centric reporting via AUC and low-false-alarm operating points. The framework further incorporates an adaptive watermark laundering stress-test that models learned restoration-based watermark suppression. Under identical constraints (ϵ=0.02,128×128 resolution, non-blind verification) and two payload regimes (128 and 256 bits), we evaluate four representative embedders spanning classical regression and deep encoder-decoder paradigms. Results indicate that high perceptual fidelity does not imply redistribution robustness; a high-PSNR embedder achieves the strongest imperceptibility (47.97 dB PSNR cover ) yet collapses under moderate JPEG compression, while robustness-oriented designs maintain approximately lossless recovery under compression and resizing. Increasing payload size further stresses recoverability even under a fixed distortion budget. Across methods, crop-based edits remain a dominant failure mode, and adaptive watermark laundering drives recovery and decision reliability toward chance, revealing the gap between benign robustness and restoration-resilient security.

Item Type: Book Section
Uncontrolled Keywords: Adversarial Robustness; Attack Simulation; Hybrid ML/DL Models; Provenance Protection; Security-Aware Digital Watermarking
Subjects: Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
K Law > KDK Republic of Ireland > Intellectual Property Law
Divisions: School of Computing > Staff Research and Publications
Depositing User: Tamara Malone
Date Deposited: 24 Jul 2026 13:40
Last Modified: 24 Jul 2026 13:40
URI: https://norma.ncirl.ie/id/eprint/9483

Actions (login required)

View Item View Item