arXiv · 2502.04901
On the Difficulty of Constructing a Robust and Publicly-Detectable Watermark
Abstract
This work investigates the theoretical boundaries of creating publicly-detectable schemes to enable the provenance of watermarked imagery. Metadata-based approaches like C2PA provide unforgeability and public-detectability. ML techniques offer robust retrieval and watermarking. However, no existing scheme combines robustness, unforgeability, and public-detectability. In this work, we formally define such a scheme and establish its existence. Although theoretically possible, we find that at present, it is intractable to build certain components of our scheme without a leap in deep learning capabilities. We analyze these limitations and propose research directions that need to be addressed before we can practically realize robust and publicly-verifiable provenance.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jaiden Fairoze, Guillermo Ortiz-Jimenez, Mel Vecerik, Somesh Jha, Sven Gowal. 2025-02-07. On the Difficulty of Constructing a Robust and Publicly-Detectable Watermark. https://arxiv.org/abs/2502.04901
Cite the original work for its findings. Save a collection to share your selection of sources.