Nicholas, Natalia Ellen, Rustam, Furqan and Jurcut, Anca Delia (2026) FLEXMark: Evaluating Watermark Robustness and Attribution Reliability Under Redistribution and Adaptive AI Laundering. In: Proceedings - 47th IEEE Symposium on Security and Privacy Workshops, SPW 2026. IEEE, San Francisco, CA, pp. 238-249. ISBN 979-831951070-9
Full text not available from this repository.Abstract
Digital watermarking is increasingly proposed as a durable complement to cryptographic provenance metadata in content authenticity workflows in the age of generative AI. However, most watermarking systems are evaluated primarily using signal-level robustness metrics, without aligning performance to verification-oriented security objectives or enforcing comparable imperceptibility constraints across methods. Consequently, it remains unclear which embedding strategies provide reliable attribution under realistic redistribution and adaptive removal in controlled image-based evaluation settings. We introduce FLEXMark, a protocol-level evaluation framework for security and verification-aligned watermark assessment. FLEXMark enforces a shared residual distortion budget, structured provenance-realistic payloads, a standardized redistribution attack suite, and decision-centric reporting via AUC and low-false-alarm operating points. The framework further incorporates an adaptive watermark laundering stress-test that models learned restoration-based watermark suppression. Under identical constraints (ϵ=0.02,128×128 resolution, non-blind verification) and two payload regimes (128 and 256 bits), we evaluate four representative embedders spanning classical regression and deep encoder-decoder paradigms. Results indicate that high perceptual fidelity does not imply redistribution robustness; a high-PSNR embedder achieves the strongest imperceptibility (47.97 dB PSNR cover ) yet collapses under moderate JPEG compression, while robustness-oriented designs maintain approximately lossless recovery under compression and resizing. Increasing payload size further stresses recoverability even under a fixed distortion budget. Across methods, crop-based edits remain a dominant failure mode, and adaptive watermark laundering drives recovery and decision reliability toward chance, revealing the gap between benign robustness and restoration-resilient security.
| Item Type: | Book Section |
|---|---|
| Uncontrolled Keywords: | Adversarial Robustness; Attack Simulation; Hybrid ML/DL Models; Provenance Protection; Security-Aware Digital Watermarking |
| Subjects: | Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security K Law > KDK Republic of Ireland > Intellectual Property Law |
| Divisions: | School of Computing > Staff Research and Publications |
| Depositing User: | Tamara Malone |
| Date Deposited: | 24 Jul 2026 13:40 |
| Last Modified: | 24 Jul 2026 13:40 |
| URI: | https://norma.ncirl.ie/id/eprint/9483 |
Actions (login required)
![]() |
View Item |
Tools
Tools