On the Difficulty of Constructing a Robust and Publicly-Detectable Watermark
Jaiden Fairoze, Guillermo Ortiz-Jimenez, Mel Vecerik, Somesh Jha, Sven Gowal
Abstract
This work investigates the theoretical boundaries of creating publicly-detectable schemes to enable the provenance of watermarked imagery. Metadata-based approaches like C2PA provide unforgeability and public-detectability. ML techniques offer robust retrieval and watermarking. However, no existing scheme combines robustness, unforgeability, and public-detectability. In this work, we formally define such a scheme and establish its existence. Although theoretically possible, we find that at present, it is intractable to build certain components of our scheme without a leap in deep learning capabilities. We analyze these limitations and propose research directions that need to be addressed before we can practically realize robust and publicly-verifiable provenance.
BibTeX
@inproceedings{
fairoze2025on,
title={On the (Im)possibility of Constructing a Robust and Publicly-Detectable Watermark},
author={Jaiden Fairoze and Guillermo Ortiz-Jimenez and Mel Vecerik and Somesh Jha and Sven Gowal},
booktitle={The 28th International Conference on Artificial Intelligence and Statistics},
year={2025},
url={https://openreview.net/forum?id=bDuNZJ6O8N}
}