logo

So much for watermarks: UnMarker tool nukes AI provenance tags

ID: 72a3f7c0-b691-5df6-ac01-f884344d40f7

STIX ID: report--72a3f7c0-b691-5df6-ac01-f884344d40f7

Feed Name: The Register (Security)

Date Published: 2025-07-24

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

**University of Waterloo researchers introduce UnMarker, a universal, offline attack that neutralizes AI-image watermarks by perturbing spectral amplitudes without access to watermark internals, drastically lowering detection rates across schemes (e.g., HiDDeN, PTW, Stable Signature, StegaStamp, TRW) and later Google’s SynthID (~100% to ~21%).** Their findings, aligned with other academic work, challenge the robustness and policy reliance on watermarking for provenance and abuse mitigation, while noting C2PA (metadata signatures) was out of scope for their tests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.