AAAI 2026technical0 citations

Removing Box-Free Watermarks for Image-to-Image Models via Query-Based Reverse Engineering

Haonan An, Guang Hua, Hangcheng Cao, Zhengru Fang, Guowen Xu, Susanto Rahardja, Yuguang Fang

Abstract

The intellectual property of deep generative networks (GNets) can be protected using a cascaded hiding network (HNet) which embeds watermarks (or marks) into GNet outputs, known as box-free watermarking. Although both GNet and HNet are encapsulated in a black box (called operation network, or ONet), with only the generated and marked outputs from HNet being released to end users and deemed secure, in this paper, we reveal an overlooked vulnerability in such systems. Specifically, we show that the hidden GNet outputs can still be reliably estimated via query-based reverse engineering, leaking the generated and unmarked images, despite the attacker

BibTeX
@inproceedings{aaai2026_removingboxfreew,
  title = {Removing Box-Free Watermarks for Image-to-Image Models via Query-Based Reverse Engineering},
  author = {Haonan An and Guang Hua and Hangcheng Cao and Zhengru Fang and Guowen Xu and Susanto Rahardja and Yuguang Fang},
  booktitle = {AAAI 2026},
  year = {2026}
}