AAAI 2026technical0 citations
Removing Box-Free Watermarks for Image-to-Image Models via Query-Based Reverse Engineering
Haonan An, Guang Hua, Hangcheng Cao, Zhengru Fang, Guowen Xu, Susanto Rahardja, Yuguang Fang
Abstract
The intellectual property of deep generative networks (GNets) can be protected using a cascaded hiding network (HNet) which embeds watermarks (or marks) into GNet outputs, known as box-free watermarking. Although both GNet and HNet are encapsulated in a black box (called operation network, or ONet), with only the generated and marked outputs from HNet being released to end users and deemed secure, in this paper, we reveal an overlooked vulnerability in such systems. Specifically, we show that the hidden GNet outputs can still be reliably estimated via query-based reverse engineering, leaking the generated and unmarked images, despite the attacker
BibTeX
@inproceedings{aaai2026_removingboxfreew,
title = {Removing Box-Free Watermarks for Image-to-Image Models via Query-Based Reverse Engineering},
author = {Haonan An and Guang Hua and Hangcheng Cao and Zhengru Fang and Guowen Xu and Susanto Rahardja and Yuguang Fang},
booktitle = {AAAI 2026},
year = {2026}
}