{"id":70835,"date":"2025-07-28T11:44:22","date_gmt":"2025-07-28T03:44:22","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=70835"},"modified":"2025-07-28T11:44:22","modified_gmt":"2025-07-28T03:44:22","slug":"watermarks-offer-no-defense-against-deepfakes","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2025\/07\/28\/watermarks-offer-no-defense-against-deepfakes\/","title":{"rendered":"Watermarks offer no defense against deepfakes"},"content":{"rendered":"<p><strong>Any artificial intelligence (AI) image watermark can be removed, without the attacker needing to know the design of the watermark, or even whether an image is watermarked to begin with. <\/strong><\/p>\n<p>This is according to new research from the University of Waterloo\u2019s Cybersecurity and Privacy Institute, which noted that as AI-generated images and videos became more realistic, citizens and legislators are increasingly concerned about the potential impact of \u201cdeepfakes\u201d across politics, the legal system and everyday life. <\/p>\n<p>\u201cPeople want a way to verify what\u2019s real and what\u2019s not because the damages will be huge if we can\u2019t,\u201d said Andre Kassis, a PhD candidate in computer science and the lead author on the research. \u201cFrom political smear campaigns to non-consensual pornography, this technology could have terrible and wide-reaching consequences.\u201d  <\/p>\n<p>AI companies, including OpenAI, Meta, and Google, have offered invisible encoded \u201cwatermarks\u201d as a solution, suggesting these secret signatures can allow them to create publicly available tools that consistently and accurately distinguish between AI-generated content and real photos or videos, without revealing the nature of the watermarks. <\/p>\n<p>The Waterloo team, however, has created a tool, UnMarker, which successfully destroys watermarks without needing to know the specifics of how they\u2019ve been encoded. UnMarker is the first practical and universal tool that can remove watermarking in real-world settings. What sets UnMarker apart is that it requires no knowledge of the watermarking algorithm, no access to internal parameters, and no interaction with the detector at all. It works universally, stripping both traditional and semantic watermarks without any customization.<\/p>\n<p>\u201cWhile watermarking schemes are typically kept secret by AI companies, they must satisfy two essential properties: they need to be invisible to human users to preserve image quality, and they must be robust, that is, resistant to manipulation of an image like cropping or reducing resolution,\u201d said Dr. Urs Hengartner, associate professor of the David R. Cheriton School of Computer Science at the University of Waterloo. <\/p>\n<p>\u201cThese requirements constrain the possible designs for watermarks significantly. Our key insight is that to meet both criteria, watermarks must operate in the image\u2019s spectral domain, meaning they subtly manipulate how pixel intensities vary across the image.\u201d <\/p>\n<p>Using a statistical attack, UnMarker looks for places in the image where the pixel frequency is unusual, and then distorts that frequency, making the image unrecognizable to the watermark-recognizing tool but undetectably different to the naked eye. In tests, the method worked more than 50 per cent of the time on different AI models \u2013 including Google\u2019s SynthID and Meta\u2019s Stable Signature \u2013 without existing knowledge of the images\u2019 origins or watermarking methods. <\/p>\n<p>\u201cIf we can figure this out, so can malicious actors,\u201d Kassis said. \u201cWatermarking is being promoted as this perfect solution, but we\u2019ve shown that this technology is breakable. Deepfakes are still a huge threat. We live in an era where you can\u2019t really trust what you see anymore.\u201d<\/p>\n<p>The research, <em><a href=\"https:\/\/arxiv.org\/abs\/2405.08363\" target=\"_blank\">\u201cUnMarker: A Universal Attack on Defensive Image Watermarking\u201d<\/a><\/em>, appears in the proceedings of the 46th IEEE Symposium on Security and Privacy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AI companies, including OpenAI, Meta, and Google, have offered invisible encoded \u201cwatermarks\u201d as a solution, suggesting these secret signatures can allow them to create publicly available tools that consistently and accurately distinguish between AI-generated content and real photos or videos, without revealing the nature of the watermarks. <\/p>\n","protected":false},"author":6,"featured_media":70836,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[853,1481,6498,6151],"class_list":["post-70835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-artificial-intelligence","tag-cybersecurity","tag-good-tech","tag-high-tech"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/70835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=70835"}],"version-history":[{"count":1,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/70835\/revisions"}],"predecessor-version":[{"id":70837,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/70835\/revisions\/70837"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/70836"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=70835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=70835"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=70835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}